{"_id":"@sphereon/gx-agent-cli","_rev":"119-2856c58a2b78224eabf65b0f91747ca1","name":"@sphereon/gx-agent-cli","dist-tags":{"next":"0.10.2-next.4","latest":"0.10.2","unstable":"0.10.2-unstable.2"},"versions":{"0.1.1-next.6":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.1-next.6","main":"build/cli.js","types":"build/cli.d.ts","bin":{"gx-agent":"bin/gx-agent.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.1-next.6+ac97230","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"ac97230ed748e1682113c361e021ff54a3233ea2","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.1-next.6","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-SevAVSy9D/qLf2jGHmkCyi6czo1R+1WLVxqt7EMgvUY5bMRqrZt+t6wfMEZ8AqfFToEQZrR7YOJdAY0CY53fVg==","shasum":"90e33b8f991e13903d79c56f5aeaf475b150a908","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.1-next.6.tgz","fileCount":13,"unpackedSize":40921,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIE8c9YBZIoRyCeZGC/jo52RtLl9Fxiw8U9jjz0A6SI94AiBxG9+ZnRMOkMXxHA8H7ufbkicCXTX/As82ltF1KyaDyw=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjyoJsACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrIvw//WxkZlQQ+QUN6+aoAcPEmudPuRQhT51BpTJLkEAuM4Sdj1LPH\r\nqtUOa5+qw/y0pZBldpi4DlFCO7WgnmIKeGe6KGX3okwymo2HKVH5jHZY1o+c\r\n1pLwMf8qzwOe3/Uv5WflxpKN7tf7sHEmLKU331olzJmtHajZVH8Zx4U9A0RH\r\nMnG5vIq29F0IJxWIaw7eA8oZBab4VGPVghk+aZ5nmccDwgDPWtrXcw+r2SeH\r\nOAfI391pYTgynQ9kLLxhOmCSGeHRF6ttgk3KdetZvEIEBtbOe1FWNqSBhI/3\r\nYcXX3jAS3/FG5qQ4e3hRBo4RlYa3h3rGjOkEU9Ehiiy+8oB6ZrvXmxKRil7a\r\nfzgbK0ydlpFyPWFMxRyovSGoxz3KAL+EQL4AaxD/9cLYcQvIjn4fUafExRDD\r\nBORLqJatZI5vwLO2RnLMKZzWjxUHb3BAxvpBaCKgB0j9Il15KZOoKt6Iug7B\r\nPJKn5Q07TVNXrwa+Li0vCmBgKA6PI95yOeL9mFpSZbt5iuS1Fy7L0eX0omTN\r\nywg8mLps+BIDhl+1lCPmhOwiNd4YL4S28zMTuRk/+5g2JqOo8WvaxX4dbYS3\r\nwKbhjfBtf255vON+rEbNtiVPx+jAAPOni9a3FPX89UeNnESWSXz5IqjgK4+S\r\nNXm8VKk2XpCY9kfUZCn56NG1sf6DKR6fZZU=\r\n=h/nW\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.1-next.6_1674216044043_0.9527757184996912"},"_hasShrinkwrap":false},"0.1.1-next.7":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.1-next.7","main":"dist/cli.js","types":"dist/cli.d.ts","bin":{"gx-agent":"bin/gx-agent.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.1-next.7+a10faa6","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"a10faa6fb0cb82304961525fe8fa6fd38593fc76","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Compliance Client CLI (Typescript) \n  <br>\n</h1>\n\n---\n\n**Warning: This package still is in every early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# gx-compliance-client-cli\n\n## Commands\n\n```shell\ngx-agent did create --private-key-file=privkey.pem --cert-file=cert.pem --ca-chain=cacerts.pem --domain=example.com\ngx-agent participant compliance submit –sd-file=self-description.json\ngx-agent participant self-description create –sd-file=self-description.json\ngx-agent participant compliance submit –sd-id=<abcd>\ngx-agent participant self-description verify –sd-file=self-description.json\ngx-agent participant compliance status –sd-id=<abcd>\ngx-agent ecosystem add –name=FMA –ecosystem-url=https://compliance.future-mobility-alliance.org\ngx-agent participant ecosystem submit  --ecosystem=FMA –sd-id=<abcd> --compliance-id=<efgh>\ngx-agent participant ecosystem submit  --ecosystem-url=https://compliance.future-mobility-alliance.org –sd-id=<abcd> --compliance-id=<efgh>\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.1-next.7","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-y410awIG0dLMy/L33WnIVZ3xhpdTvEBxF0hLUbkJpxeVtMyG0TDZ8+YUPstFThIPq3POf+fdxQJR+n/ZpwliNg==","shasum":"557be4444dc141f41f4918aba9fc7642fafbaf1b","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.1-next.7.tgz","fileCount":14,"unpackedSize":41559,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIAOIBpcGbYdhZ8KI9IrSGmga0VHvN254dLWhWlizG5bBAiEA5U+3GWgaRxyCDqltzkB94lm7wu0erYz8z14BCd21R1w="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjyoj9ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqYiA//bnHgYT3p01VS//wNiVD3ZWwMItpjcoPBh13chueVO+LdRucI\r\nM+drCmLOFoHdNr1+4e7QQtm85eM12RTl3o6NXLLUhYSS/No+ccyygKw4A8h0\r\nw7nYbZzAlLIxcqdnlrIa5OyoRiCLb+iIm0CdptOG/IriXEoKgbPuBHP8Hv4Q\r\nZSqtWEMvWP8Cwv/g6gbZ6P7OZcBXImxeY+q3EFxrKWlE8LuW6Bw2Ha8Z470H\r\nEZ387QFEzbNbbOMECx6mJ/0kPxmBQXtewJM+pvHd9gJsR1bDDIDDncIFIcXn\r\nvl388Z8rEDKIv4K/EVJToOISSwDjSdc4B2TS3KD+nf0qABzVcu4HEvGyGTha\r\nc1g/orVOFJyWb/yuYZznUdmQ2NRt24H9BEITJ7Yrx0hs/VT/b6gLO/RXHqKq\r\nrJCBZMUu3x18iaxvAAsJO/BE3BlRayqkXKySkF5mTWy0AlJcGjK16g/S5WfD\r\nR5RemPFwwWWg/bA1GhBhICZ/cNfAbDiwshuQh9K0TgqLW5hKrI7VfwntEyUf\r\nfJ+Qia7YkVFSY9kZRcFlTB3JvvGjxlqXsDJP0v3Or/edbowvjteMosPHTUxN\r\n7Ci0keJz9I/QLORgly985XeDvBm0fsz1cdSHbjeJXhjpq27qPbOzDXkFOBaJ\r\nSfKyl9JEe7/ekkV2XXguLaiyoY8NT4g39vA=\r\n=sVCL\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.1-next.7_1674217725644_0.6612216345291049"},"_hasShrinkwrap":false},"0.1.1-next.9":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.1-next.9","main":"dist/index.js","types":"dist/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.1-next.9+7fa5077","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"7fa5077e6438281159e66a4d9ab65f510ec2f899","readme":"<!--suppress HtmlDeprecatedAttribute -->\r\n<h1 align=\"center\">\r\n  <br>\r\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\r\n  <br>Gaia-X Compliance Client CLI (Typescript) \r\n  <br>\r\n</h1>\r\n\r\n---\r\n\r\n**Warning: This package still is in every early development. Breaking changes without notice will happen at this point!**\r\n\r\n---\r\n\r\n# gx-compliance-client-cli\r\n\r\n## Commands\r\n\r\n```shell\r\ngx-agent did create --private-key-file=privkey.pem --cert-file=cert.pem --ca-chain=cacerts.pem --domain=example.com\r\ngx-agent participant compliance submit –sd-file=self-description.json\r\ngx-agent participant self-description create –sd-file=self-description.json\r\ngx-agent participant compliance submit –sd-id=<abcd>\r\ngx-agent participant self-description verify –sd-file=self-description.json\r\ngx-agent participant compliance status –sd-id=<abcd>\r\ngx-agent ecosystem add –name=FMA –ecosystem-url=https://compliance.future-mobility-alliance.org\r\ngx-agent participant ecosystem submit  --ecosystem=FMA –sd-id=<abcd> --compliance-id=<efgh>\r\ngx-agent participant ecosystem submit  --ecosystem-url=https://compliance.future-mobility-alliance.org –sd-id=<abcd> --compliance-id=<efgh>\r\n```\r\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.1-next.9","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (win32)","dist":{"integrity":"sha512-+fQCqZbfkAdq2YQcQNZBI4FvqoMJnq2g4X5NqGSBUn7S3q6IuQJeQN3advUzwLbcYvT/S5cxuhfm+ayQ/avjjQ==","shasum":"487d30b6e8e928673da9c7d5641b76e4474b10a1","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.1-next.9.tgz","fileCount":43,"unpackedSize":81296,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCRYJ3R0+npPbc77pp9W6u+0AziDulOlqRbWf4qUec94wIgb+T9ywRpWOei1ZzoFMlasZ2Oz08AIlXB/KF7E7Uc2+w="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjyyWPACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpWoBAAjiYqyWsOMnPSYGI++ddOj52T9pDnCmXIY2HWF1Bkdk1ZJTps\r\nie7XLBrMnFB1afsqps9vsgVMZbEESHjV91G5OV3nm76rKUMOQXB+4RpTwidZ\r\nTbrYBz0nRNzxam7Xkp0D/PaHSulNarYmxK8ZVYP3pkwUpE73PsbZZW7Zqi81\r\nVPLc+8PCKtCZL+oZfuP3n5tkxOS++6dnq0hjSKMseTRtViQWE6LJxiZqtowr\r\nkeI4cYR9E3MiDO1s1igVqJa0csKX8nmbUbClcijVR2kuSZHoW3RBH7MrLsQm\r\nsnVnXR4l4YIHhFO5NQ+r0dZIiglBQhP1BtXV8CsocKf585insRsuMhp68Jd1\r\nygYWE3XrTeYc2yoIaEBVUFGmMY/qpGlgR1Qybr5e4+Kqt4PaNJAo4UMGtMXF\r\n17LujjDfkpeJ2WzU2FVeXx34qHcbFZqI2EY1TilJY0Xvqzgxi9OA26esubTQ\r\nQsSxWBCPXxepshmKnzxnGpo01IF/nHMprmOW5gBeIzfnoeH9zGhcSep6HGXv\r\nXu1UhIML6QYhNiFaQI9O6X+B+ny2VfMB1fy//HLwoTGGg3fjQ9eOUm8N6pie\r\nIqXFoh1zpjN7/nIOsqxZeo7CUoYIK6jXWpIjUnW4CrL916PeK9MO792NUMxc\r\nWZyceXbuU+sOtgI1TSoQaYjzB1SjSUP9PCI=\r\n=yxHo\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.1-next.9_1674257807052_0.42759622904320116"},"_hasShrinkwrap":false},"0.1.1-next.10":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.1-next.10","main":"dist/index.js","types":"dist/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.1-next.10+7db7634","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"7db7634d26cfce421b8c5aa407a8342c6d65d987","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Compliance Client CLI (Typescript) \n  <br>\n</h1>\n\n---\n\n**Warning: This package still is in every early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# gx-compliance-client-cli\n\n## Commands\n\n```shell\ngx-agent did create --private-key-file=privkey.pem --cert-file=cert.pem --ca-chain=cacerts.pem --domain=example.com\ngx-agent participant compliance submit –sd-file=self-description.json\ngx-agent participant self-description create –sd-file=self-description.json\ngx-agent participant compliance submit –sd-id=<abcd>\ngx-agent participant self-description verify –sd-file=self-description.json\ngx-agent participant compliance status –sd-id=<abcd>\ngx-agent ecosystem add –name=FMA –ecosystem-url=https://compliance.future-mobility-alliance.org\ngx-agent participant ecosystem submit  --ecosystem=FMA –sd-id=<abcd> --compliance-id=<efgh>\ngx-agent participant ecosystem submit  --ecosystem-url=https://compliance.future-mobility-alliance.org –sd-id=<abcd> --compliance-id=<efgh>\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.1-next.10","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-RsrOY3b0OMV+X8WMLRKSi6lPTRcfqgH+UmPMsf1cP8AmP1cisbU9dXFUh4qKC/B++Hi6gC37DBAVsNWM+lZAXg==","shasum":"8321f27a9c4db30e6c380452c9172b67f7345931","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.1-next.10.tgz","fileCount":43,"unpackedSize":79605,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGNMWYeer/T7J4UyQi0XU2Nz2BxyrLvGZLy5ozA/CSpKAiB5TedaAaUwWoOxf4HPRttrygameX+VFKGM+esFXMt9ow=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjyyttACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq0bhAAnSE7okTNENEU2upthu2/t0VecfKYEu7bEGI8M/FfAhpvou1k\r\n7pwU7FQESebGqBBQDnwM5iwbuAGI3MC+mm9NrhuPzszvmHFHbWvEmJPhnaQs\r\ntyCuHF4iqMTINJkla3HPKvn4qVmBaaUFhJlJWEaz4KNnczjF8pwtaEowfhro\r\nZ2ndIhAeKvJ7+ErdDu85Hascmn+jfwlMQO5xRnIbIQc1x62VA5PO381AIO7v\r\nRAw3Py7MMQ55ogodwGFuZPwGAcrfzs6DjX8g1G1zGMQ4/ZxTc5A3KEFush79\r\nbiqNeVRiYtMf0e0BY2xWlMUNel3R8kJxDjrmGqr1dNG2jH11dNgPJSWKApf/\r\nUokSJUcN0uXNDVNoA9E3T9yvIa6fEB77KIvvqgLplmRi89YARmX267qKxOMr\r\npnzYaU9xmWNYkeuT4kWqSdqPVpFiTlQql8jHdFBm5veXDO9lZAu61K1tksq5\r\nvjxWonLr2uwV8w73BKU5oXv3G4cDloLXmH+OiP1q0adtaCwPuUIRiRqcPscg\r\ncF6YumA/p3v2knXepcU8u2n/pHJuiCsrr3PnfyXZbNbg8ttHhllZnL4rDZCj\r\nrTt/4hE0H3s9cSBVcYbG1/n330sVgCMYVi7bHqfjkuezZR3BS5RTcpEnnAI/\r\nLi8s4XIIWr2QxwDMUAAxqusf7+Xr0fTX8tY=\r\n=kfIc\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.1-next.10_1674259308841_0.8758008315081001"},"_hasShrinkwrap":false},"0.1.1-next.12":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.1-next.12","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.1-next.12+e375e1f","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"e375e1fa756202463c2d4e3742cd58183f53c17a","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Compliance Client CLI (Typescript) \n  <br>\n</h1>\n\n---\n\n**Warning: This package still is in every early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# gx-compliance-client-cli\n\n## Commands\n\n```shell\ngx-agent did create --private-key-file=privkey.pem --cert-file=cert.pem --ca-chain=cacerts.pem --domain=example.com\ngx-agent participant compliance submit –sd-file=self-description.json\ngx-agent participant self-description create –sd-file=self-description.json\ngx-agent participant compliance submit –sd-id=<abcd>\ngx-agent participant self-description verify –sd-file=self-description.json\ngx-agent participant compliance status –sd-id=<abcd>\ngx-agent ecosystem add –name=FMA –ecosystem-url=https://compliance.future-mobility-alliance.org\ngx-agent participant ecosystem submit  --ecosystem=FMA –sd-id=<abcd> --compliance-id=<efgh>\ngx-agent participant ecosystem submit  --ecosystem-url=https://compliance.future-mobility-alliance.org –sd-id=<abcd> --compliance-id=<efgh>\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.1-next.12","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-G6r46tJZutIDAaOzUD8JB4qzhjkup1qZm/DJYyMaGUo9Tt8aHeve/i2g54/dYE7bffiSHXhDBAIzbhs/hYI4Lw==","shasum":"48130ad70e71773ca4f94267273ad62a278cdbc5","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.1-next.12.tgz","fileCount":34,"unpackedSize":216175,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDzvMLETw5Y5z2AO+zZlsRRR9kAaicK7jbHZd37GfffPwIhALWhm+JsgWMj+X/y64tVHvCDFCn4qi/P37+gSFC2KLHO"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjyzRlACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrNBQ/+LVU4F0RJXaUKR2jUVfvp+TMW+3LmmekRkXfcFuKdmqrVchuZ\r\nVSVNU9ze0/Z08ENPxdGHEePJlxoq/9+XSAJvuCooVaD/tuAzdbx2zCQG7YbS\r\nGeCxk6omjhbyTlFJoxvbhkRHSoYFySSLjRM6WrD/WyehHecfHN7+lwFjm+25\r\nRJdTxpfJ7eJ37ufGbZJN/rmXE8fR3CVN99sn6DFr5sBCs19nydaYwsZx6u4L\r\n+1R5tHbGx6VNoJiW1X3Mi6Ww6zJoF0uM3b2p5IRFuR/a29HnMw+7uyUMRVLK\r\nxJ9LQP/HWce2+qhheLsFJZW0MwUdHruFlSxlZoohDiw9I9hN1gGcpOUGQV9L\r\nBrN6GnuO7yvH+wBhEIeNeidgHPB3JYfz2q/BsA8nktIyqNDGVduE58wiHQHO\r\nK8C7gehCD89Up7b17TWq0qFappf0JIGkhZf9x7wZm8/Ox2n5kCvrCvHWBIvV\r\nf7S38MSoTgEAGQd5otRPiWux+1zBSdcNZjsXubdlLFz0f/KT1aRiwGkpH22z\r\nw4BrTADHLO9X9Cknsb6bHXXpdf69EoQev/4ETAZewVUcs3h1whmUOjUCEl5Z\r\nQwPqSh3tdJVHQL42dX0yRj34qJsVaRWJHEGleKGQKo+B4/t0CdvfN6oCXWUf\r\ngZ3ZYRRS+L2SIjpZa1Xk80gvG/eRlphLkpM=\r\n=8YQj\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.1-next.12_1674261605201_0.6535099703906022"},"_hasShrinkwrap":false},"0.1.1-next.13":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.1-next.13","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.1-next.13+a1d3a2f","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"a1d3a2f0e61db2d990e700433331d5cbcc150077","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n### Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain=path/to/cacerts.pem --domain=example.com\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n### List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n### Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-compliance.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-compliance.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n### Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │      did.json │      ./my-export/nk-gx-compliance.eu.ngrok.io/.well-known/did.json │\n│ did:web:nk-gx-compliance.eu.ngrok.io │ fullchain.pem │ ./my-export/nk-gx-compliance.eu.ngrok.io/.well-known/fullchain.pem │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-compliance.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n```shell\n\ngx-agent participant compliance submit –sd-file=self-description.json\ngx-agent participant self-description create –sd-file=self-description.json\ngx-agent participant compliance submit –sd-id=<abcd>\ngx-agent participant self-description verify –sd-file=self-description.json\ngx-agent participant compliance status –sd-id=<abcd>\ngx-agent ecosystem add –name=FMA –ecosystem-url=https://compliance.future-mobility-alliance.org\ngx-agent participant ecosystem submit  --ecosystem=FMA –sd-id=<abcd> --compliance-id=<efgh>\ngx-agent participant ecosystem submit  --ecosystem-url=https://compliance.future-mobility-alliance.org –sd-id=<abcd> --compliance-id=<efgh>\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.1-next.13","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-frHgr9EVPKsYL4wDUDhYCOgZpMTvo7XliwouZ+QC0ur+CrtFlErTfHiBbw3KSNKqAChIopiGInhGp3nmMc+n4Q==","shasum":"3ac8dfcac2030791df88d2c8d85afcf498c1c679","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.1-next.13.tgz","fileCount":44,"unpackedSize":258892,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIC6HKC4en0DazqOkX99UX6JXQT+ffv7oqXCXIb7Ls81DAiBe9PEc9t8mbAuWDpJenblxLpqu+lUul5ijoRGR83pIcQ=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjzha4ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpd0g/+K2VcHZrw0Sxm02DELi5B/q/gESEZppfmM4NzWYyb5lMPNFxs\r\n6gHwgUxWCED/2fSuxfJbYLpyeq6C14JyzgorRx2jvwxmwFHpSvkooUmAMh+7\r\n+n8mY/hiTx1lbjlu7bIcy97epiiHQi8Pyp0rbDpuos/Z32a0AXDw5d9vAstX\r\n65XHDSIrAkj9B6ih+H3LTVttLiTxSHxcr8W9uYDvkhpczjocyhT/QJ19anrE\r\nzR3yNfFANm57ESnS3H3fH5Eh7rhX1cPi5L3T71p+Mh8P4wV+oeLTd9ocFRjS\r\n8V4edfYZ5tsfaMZ4kp6hN8Woq+zVp8vuELbD0ijgpdq4/zX8yQIUo8PRfea8\r\ndI9KhE36URf0LkRyfu7ytApF8cwCI4CrJQ2VMNMlcDterkpDPXAJa8b+IXj0\r\nj00j2sLmhzZMPHAgbVmYYS2mD2b5aus9OmmVHi272zZ0M9KSi/vXP2JtHltR\r\nmcPNq1zBH+J2KMCdCahg/kUKbbd6tj4z7cUMXBsEjza254Y50gZpwJuNxe1y\r\n15xD/zoM4wZ8+KU0psjBjjjT51IrdztWwysuoBct2z7ygzvUJwdo8P4su6PD\r\nRCXiTuADOiGQu6/C2oC9Sa01fjG/SBc6EwlV6IIbXZM+YOIU8/yChuNpD6z7\r\nUT5DaCUkiNEAzrQbZT4ri58p3SVvEx3MqHk=\r\n=gJ9M\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.1-next.13_1674450616260_0.6331396181711675"},"_hasShrinkwrap":false},"0.1.1-next.14":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.1-next.14","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.1-next.14+b7c535c","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"b7c535cb7a0264f31c92cbd7d5db365f86119e50","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n### Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain=path/to/cacerts.pem --domain=example.com\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n### List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n### Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-compliance.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-compliance.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n### Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │      did.json │      ./my-export/nk-gx-compliance.eu.ngrok.io/.well-known/did.json │\n│ did:web:nk-gx-compliance.eu.ngrok.io │ fullchain.pem │ ./my-export/nk-gx-compliance.eu.ngrok.io/.well-known/fullchain.pem │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-compliance.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n```shell\n\ngx-agent participant compliance submit –sd-file=self-description.json\ngx-agent participant self-description create –sd-file=self-description.json\ngx-agent participant compliance submit –sd-id=<abcd>\ngx-agent participant self-description verify –sd-file=self-description.json\ngx-agent participant compliance status –sd-id=<abcd>\ngx-agent ecosystem add –name=FMA –ecosystem-url=https://compliance.future-mobility-alliance.org\ngx-agent participant ecosystem submit  --ecosystem=FMA –sd-id=<abcd> --compliance-id=<efgh>\ngx-agent participant ecosystem submit  --ecosystem-url=https://compliance.future-mobility-alliance.org –sd-id=<abcd> --compliance-id=<efgh>\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.1-next.14","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-XXmmD8Palf0+PEQoroncPVivlvWoeoew5eHs0uXm0vOQFN0V/1ggikYjeuRzgTjc8ceHzSr6xEGGg0+9icCHeQ==","shasum":"7813e8f12984a6e06112319d0c2a53c613406b5c","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.1-next.14.tgz","fileCount":44,"unpackedSize":258892,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDVKnirPVUiA9bc0WUaCwJbBNQmH6GEJnLe4C+uT0xC3wIhANhijmPIyEV+M4fsj+6WWZJU+QJDLTLrv5GEhwgiek9G"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjzlcoACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmprCA/+NS4Sh23g5Nt5jVjJn5kPJiCiaS6qoq2hWgO4O13bvDfzOlIv\r\nRAHJ2Wxhr0fawOsc7R2XdQUNDkw9cw9L2ARSV93wZWTNsbQMu21SKdAQ6WyP\r\nzbNfKDGyjX7pLxz2QyCfAVwAyZcljUBlZIoOfg58m3RM2l4bq0JpI7A475CQ\r\ntTKGMQweYzCzBJsYLO+KcD6cRsZhpHdSvarRZpBvIIEt7mNHU2CW2jYF8N1f\r\nQoniSESn2s1p/h7qMwxANRTZMDDeoMIh37qbEFC6vN3Hh8glET48CUz4ldM8\r\nVGoL4r1uQYRYz/ZYI9RKiMmb84MpsY21K7tEnEP6OhWFcc0xteUQua3nwv3t\r\n6R2oYM1eZYJJik/n8kPl3cAkKPEObj6xUDjpjQuaojw1GjkSs26Ff7agED+e\r\nLWv2u0y5lYiH3JwdlyhriqauzvuC3PghKfNRgjYpLMKqWgVNmxGmoFMH4O6S\r\nreSDMlxqESFScnN64+jbEPSjmoPMr6N2f5PFTmiBKJTwFIsPpN+/RfpC7Bve\r\n7gm1NM9PeK6aTDGleo0mDHQcpAfDMwNAX5tSu2bjhIZS0D6MsM0/6eFUbV9b\r\nDMGBP8GTdTcTBt7D7QpIjCx9RKs0gjdtdLiWaqMpcVobml4HFCiZccKFPYPB\r\nVp//4VA84wOVcB5o+AnnqXbBlLar1Nl4pZ0=\r\n=YahM\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.1-next.14_1674467112233_0.38279496216955144"},"_hasShrinkwrap":false},"0.1.1-next.15":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.1-next.15","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.1-next.15+d5dd12b","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"d5dd12b462303357d9fad3bbbf2e136be0428cd3","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n### Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain=path/to/cacerts.pem --domain=example.com\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n### List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n### Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-compliance.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-compliance.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n### Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │      did.json │      ./my-export/nk-gx-compliance.eu.ngrok.io/.well-known/did.json │\n│ did:web:nk-gx-compliance.eu.ngrok.io │ fullchain.pem │ ./my-export/nk-gx-compliance.eu.ngrok.io/.well-known/fullchain.pem │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-compliance.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n```shell\n\ngx-agent participant compliance submit –sd-file=self-description.json\ngx-agent participant self-description create –sd-file=self-description.json\ngx-agent participant compliance submit –sd-id=<abcd>\ngx-agent participant self-description verify –sd-file=self-description.json\ngx-agent participant compliance status –sd-id=<abcd>\ngx-agent ecosystem add –name=FMA –ecosystem-url=https://compliance.future-mobility-alliance.org\ngx-agent participant ecosystem submit  --ecosystem=FMA –sd-id=<abcd> --compliance-id=<efgh>\ngx-agent participant ecosystem submit  --ecosystem-url=https://compliance.future-mobility-alliance.org –sd-id=<abcd> --compliance-id=<efgh>\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.1-next.15","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-h8652iuuhGAf4CkSBX1R+9BMX5CE/XH0SMsXA3Xzo28rbYIYSEomjMDfEukNIUtDJQJJNmPRBHu3J8oZO8FqQw==","shasum":"ea178989a49fb5e88bf1d0e05636fd45b02b9b4a","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.1-next.15.tgz","fileCount":48,"unpackedSize":280934,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDqC+MADyv8iXaeX8NpDhwQ8n1aP9rwAYOJ9hIyycGI0AIgZ7euHvU4BWdHkjzPutOhYR3pup19+7SstkCI9MSDbfI="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjzoKsACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp1QQ/+KW8Bsis0qWKfDPW+jAS/ynOwD9avFofGR4emmUKFYief899r\r\nGjBWfSHJL4dZGZ322MJWIsn5NyczNZ0+eBr1NGhQR+5gP+6o8wJ39yksnxH+\r\nyUOPFH+NQHaS4ME+6jn5eDxwEFbwbcrMCF701X+62VMpMgBjJXubdiH7GfPf\r\nC/k6pdi56cJDO/b4ZADE6PtUNzvakxqB8MhuEaZc269DuCtvP29DE7elws6r\r\n8Mb13CTolmM766LwjP12qlyAPyvCxob2HWmxQ3j5g44iys4+b5ufqcVSLT7M\r\nGb8iQrUdKb8hxFw/T6dD8Cgsikl5oPHMVdIqNxnZVrt7l/3XAvUQBOo/yvwq\r\nQVeV7m3qdYADq28046/rpDJJPujMWXSi0jEwqQ/Acjy71WJOESAQFUruKD71\r\ny4a1nsDXGGkUIRjhRK0IDAeyzn6QAT4dype9Tk57+cP7tbjgj2XPcy/YAVZ1\r\nT3+a2j2jcJdfuUKdT9yFUdO+WHJW4/2l+utQbVpWNXlGYlaS9y0khXfN54E5\r\nF81V3+APeY9kXhJU2iYro+t3P9HonBiRBuIxsC4CZr3581sdk9T4ivzZvGbr\r\nS8MyroV4dKNdZEQiXLeghpdtBhl6yFyynZhYk/vm1is99HxMvBRp1WebRy5b\r\n/vYNdy2OzP32nFPQ4oMO4QjTYG/vGYciiaA=\r\n=EKmF\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.1-next.15_1674478252058_0.04235104609841844"},"_hasShrinkwrap":false},"0.1.1-next.16":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.1-next.16","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.1-next.16+b70ed1d","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"b70ed1d115786ffc9c6f198274b2468fdb5a618c","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n### Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain=path/to/cacerts.pem --domain=example.com\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n### List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n### Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-compliance.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-compliance.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n### Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │      did.json │      ./my-export/nk-gx-compliance.eu.ngrok.io/.well-known/did.json │\n│ did:web:nk-gx-compliance.eu.ngrok.io │ fullchain.pem │ ./my-export/nk-gx-compliance.eu.ngrok.io/.well-known/fullchain.pem │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-compliance.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n```shell\n\ngx-agent participant compliance submit –sd-file=self-description.json\ngx-agent participant self-description create –sd-file=self-description.json\ngx-agent participant compliance submit –sd-id=<abcd>\ngx-agent participant self-description verify –sd-file=self-description.json\ngx-agent participant compliance status –sd-id=<abcd>\ngx-agent ecosystem add –name=FMA –ecosystem-url=https://compliance.future-mobility-alliance.org\ngx-agent participant ecosystem submit  --ecosystem=FMA –sd-id=<abcd> --compliance-id=<efgh>\ngx-agent participant ecosystem submit  --ecosystem-url=https://compliance.future-mobility-alliance.org –sd-id=<abcd> --compliance-id=<efgh>\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.1-next.16","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-13bWxJlqZ8sAu0HdLZk9Szc7czJHLT6ulC0EOBwAD5GjJnNPUbys/vm1AXifqjcWyWPmhCM38UeWOCKjUxH01g==","shasum":"c697a042135908d123172fbeb1329b19abd27d07","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.1-next.16.tgz","fileCount":48,"unpackedSize":281046,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIH8Vd3t8q4GrQS/BQAMjVDgccFnqAlYixw7UKpsv6XolAiEA83FWcXC4Kk1M/raIoBvsVdKJpjA8Oj5q9TeYLm51ulE="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjzol/ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrIfw/+LB+Ccv6nkIdY5/eeh0v/OBkDAUQATbIhLd/yHppD39tg+MFM\r\n5jBz7BAxXcoim1Qu0Nv0hTBedHsRtoUzE1ffQltz+cgb+N+3YGI5D+zySVE+\r\nYZMDPO5kMGgVj4PxIvFEyHGXDTf362SG0LaGBFe+gFNNyLzK5kBRSLLo2UTk\r\n2PThAT3p46ZASZyr+XPmuYwVHf8CBofkcq8+QgATaCL2vJ8zg9CJr+dTlGfQ\r\nHHH2lVJnar+4l+YaTn+ugxkEpccq9WhTrJJMwfoRiP7bVQTITs6XikRSAai3\r\nB2M2LSIaWXRNfIWECbMTGcXzDWN6lzsia/Siduql3MbUBXHCl7Mn/wipJUL+\r\nDdPzSdcznXAZcBe2yqzqGMXSZMkXbSEQ643DAO46Z0OYyK90IjcNR+B50KvJ\r\n9DJJmw1heZ6I4g6qmsxoXGN0nsZqYpI0BUG/O8uoqxcyx2PnmRpg2cDRwae6\r\nwwHXNXgXfNMAcqymys87doPuKnDrbMb8vZz7wxGcrj7j0cpEsTFBwEk+Lb5W\r\nbdTIvLIQZfEm0irAsChHcm/Wm+Velq0CAUccTyhQdQcE3Z7r484T3DixT4tp\r\ncwtWszkZdr6rpcH/x5A0P8RmCYOT0f7xiTLuRbKjyptzmjY1XVj3gIbRMM1i\r\novNxIK3k+txPK9OeuvSbPHrZDxREWlMF1+I=\r\n=0/nl\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.1-next.16_1674479999556_0.6498310741138624"},"_hasShrinkwrap":false},"0.1.1-next.17":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.1-next.17","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.1-next.17+eb523c4","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"eb523c45ee66f0cbe9b64a6c595ca061a55c4fc4","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n### Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain=path/to/cacerts.pem --domain=example.com\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n### List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n### Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-compliance.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-compliance.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n### Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │      did.json │      ./my-export/nk-gx-compliance.eu.ngrok.io/.well-known/did.json │\n│ did:web:nk-gx-compliance.eu.ngrok.io │ fullchain.pem │ ./my-export/nk-gx-compliance.eu.ngrok.io/.well-known/fullchain.pem │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-compliance.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n```shell\n\ngx-agent participant compliance submit –sd-file=self-description.json\ngx-agent participant self-description create –sd-file=self-description.json\ngx-agent participant compliance submit –sd-id=<abcd>\ngx-agent participant self-description verify –sd-file=self-description.json\ngx-agent participant compliance status –sd-id=<abcd>\ngx-agent ecosystem add –name=FMA –ecosystem-url=https://compliance.future-mobility-alliance.org\ngx-agent participant ecosystem submit  --ecosystem=FMA –sd-id=<abcd> --compliance-id=<efgh>\ngx-agent participant ecosystem submit  --ecosystem-url=https://compliance.future-mobility-alliance.org –sd-id=<abcd> --compliance-id=<efgh>\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.1-next.17","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-sWpUNXV8HFFrArMu9h2rz42kLOvuuroCKvhHff+4OfPPDFAQGXcwsnNUUGGRHzXoazjL3paFmWCovSemjci7EA==","shasum":"23f5b8b6ad4d75ac81f02979bb150183df928c1e","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.1-next.17.tgz","fileCount":48,"unpackedSize":281046,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDV8z/j5v2waZF82nbjX8GN6kJ5M9xT/Q+yKgMBS5AecQIgL6snczy1gQbY//OJgck1bf7Xx/W+zWQisfrHdaA46Nw="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjzpPSACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqpVA//SQSGKHJ3dIaOSfS/5/mh2AKO4I01QHxTGQcFOYC1vsK9ePOq\r\n4Jo+N7fjOwfAhJ6lNBxhHksG9EbZJImel2kj6XOSCnPu5wgTWDpn/y6FbCgn\r\nBzRCOpERFSBj/BovNo3cESPIXSQYM+mDaU5ot4DRt6JExJJ6byZPzoBZJu3P\r\nc9V4+t5UoWQo5XaYuFW9j3TAFd+A/tTLlptVidufPoPRIS+fbNOjerY2k87O\r\nTDu0hphnES/KRKs90f9u/dHMpWf1TaAhwY7BiTXhBgIltMFpGTQlVHdsKAIn\r\nKzxbGhFI+D4lHVgdpjrdSTxnNCsmGM3cmr5k+LgnJvfXlnKbw+0VtFXUsRul\r\nM5O0rN0NWlAs4KiOF0cAEMzUymsYd1M2X3kRaYO2IhzOPi+j4KMQpm4DXExj\r\ns0i30JiHmsqAf4j3sm4vRWcoV6JdFESzX2j5BHmNDW0FWQzlZBNtNQEEI4qG\r\nqmpBL+/pbU/j4dSwNK4UAdbJJJ1vwcQMzX4DS6vXV7sF62zkyi43DqZh9da1\r\neDH4uSAckFhcXGsNkawiT4pptEnjxV1ReUWJUruxwn/jJ/InGRDHQG6NBvfo\r\nO4vPXqRwpGEgJXMyDxTJ0bgi2DxU6U4dkKWxTX+owLqUY30o/aXAXXcchStM\r\ncV/zVg5QB6qm/oALU7qmwxoEz2s5LhEq0os=\r\n=vsx6\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.1-next.17_1674482641885_0.15538909015844338"},"_hasShrinkwrap":false},"0.1.1-next.19":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.1-next.19","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.1-next.19+1d192b3","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"1d192b3569c26986f285a199942208ca37341eae","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n\n# Prerequisites\n\n## NodeJS version 16\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following page: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions \n\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain=path/to/cacerts.pem --domain=example.com\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-compliance.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-compliance.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │      did.json │      ./my-export/nk-gx-compliance.eu.ngrok.io/.well-known/did.json │\n│ did:web:nk-gx-compliance.eu.ngrok.io │ fullchain.pem │ ./my-export/nk-gx-compliance.eu.ngrok.io/.well-known/fullchain.pem │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-compliance.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n````shell\ngx-agent did delete did:web:nk-gx-compliance.eu.ngrok.io\n````\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example self-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n````shell\ngx-agent participant sd export-example --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-compliance.eu.ngrok.io │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n  \"id\": \"be284e34-665e-4759-b2f0-4e9af6b9f742\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"https://participant\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"localCode\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"FR\",\n      \"gx-participant:addressCode\": \"FR-HDF\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"FR\",\n      \"gx-participant:addressCode\": \"FR-HDF\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n````\n\n\n\n\n```shell\n\ngx-agent participant compliance submit –sd-file=self-description.json\ngx-agent participant self-description create –sd-file=self-description.json\ngx-agent participant compliance submit –sd-id=<abcd>\ngx-agent participant self-description verify –sd-file=self-description.json\ngx-agent participant compliance status –sd-id=<abcd>\ngx-agent ecosystem add –name=FMA –ecosystem-url=https://compliance.future-mobility-alliance.org\ngx-agent participant ecosystem submit  --ecosystem=FMA –sd-id=<abcd> --compliance-id=<efgh>\ngx-agent participant ecosystem submit  --ecosystem-url=https://compliance.future-mobility-alliance.org –sd-id=<abcd> --compliance-id=<efgh>\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.1-next.19","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-TtV/3qw8Gu9/L2C3/IB+UsLb7j7+Okvsyy4w35pYTIH6XfMNS2yMNZEwbH08KF5jpf7VdPMSvTxIOjh/KfoUvA==","shasum":"8d21e3720fdaa51c4957455b6733c2f56e53d1b2","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.1-next.19.tgz","fileCount":48,"unpackedSize":285989,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDhX77k3ZmbIl2RTmh35sfJpAD5/0OgNrpuln/6hAjMiwIgYitZd87q12K7i5t3Cnkbo1e61+QrA5CbysmcMG1Op4I="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjzpUXACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqRXQ//Yx+o7ERFWa3X/6XqAFi2FW38ZBh3mQMBqnMqOI6/cSN5xejq\r\nOM3Wc3r1uixYl7A7GznerQy/l16On9TqtYzrntNQYwXKCOFBR+MbCUToqu+t\r\nnCgkzRED6OtwzJUqUP03XY688VBMAfGY6pvqvqvI+UL+ZwLqN/Drx1S7dskx\r\nB6gQwiVX2y/6PnIcdapJ8qyZSoCjplYnxk5puhQrIIPZnbQvxfwtIy55oOru\r\nIwvmsAvQ7mOaV0cDgJCfBy/GSv6PrvjOdhNtFqagCh230+AVD1kLpqaB7rjO\r\nqBslVtB6pwd987DQ8UedyUZ6OUw6O1tPabCRm0oLwplYymUACNPWQa4D3lEp\r\nBX6mKrePJ7U+cU+U6gnMgxfzX676up68IkMXgyg/qaXA2VA37d9qWocFOvpK\r\nvJgGviUqjjYfjetn+fQbcVRZcibQhUk1I07Rkyr86+LJXzlsckzIN3WJLexV\r\nyGFOr5Kzel5vZan0jmYHmwe/75yogpNXSx/gpkv4MdyFmyft1X4mi3/Deu58\r\nj4w48UGDliLro2ETAYnx9kCYPzll6ez1zhdkTRWPUKcEpAPl2iRGePQgIyUr\r\nln9mOAnBFQB7XWrrujIm3gVUE2XI/icadlC2eZixVVV09yNcFM+j0438MMlH\r\nDFUA7r8yWu6yGj4yz1j2kM5wkXJPL3raiG4=\r\n=j2w9\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.1-next.19_1674482967641_0.0755567219251414"},"_hasShrinkwrap":false},"0.1.1-next.20":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.1-next.20","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.1-next.20+5b6a40d","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"5b6a40d8a927ac140007b6345b1c47a3dbb30f46","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n\n# Prerequisites\n\n## NodeJS version 16\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following page: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions \n\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain=path/to/cacerts.pem --domain=example.com\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-compliance.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-compliance.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │      did.json │      ./my-export/nk-gx-compliance.eu.ngrok.io/.well-known/did.json │\n│ did:web:nk-gx-compliance.eu.ngrok.io │ fullchain.pem │ ./my-export/nk-gx-compliance.eu.ngrok.io/.well-known/fullchain.pem │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-compliance.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n````shell\ngx-agent did delete did:web:nk-gx-compliance.eu.ngrok.io\n````\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example self-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n````shell\ngx-agent participant sd export-example --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-compliance.eu.ngrok.io │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n  \"id\": \"be284e34-665e-4759-b2f0-4e9af6b9f742\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"https://participant\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"localCode\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"FR\",\n      \"gx-participant:addressCode\": \"FR-HDF\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"FR\",\n      \"gx-participant:addressCode\": \"FR-HDF\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n````\n\n\n\n\n```shell\n\ngx-agent participant compliance submit –sd-file=self-description.json\ngx-agent participant self-description create –sd-file=self-description.json\ngx-agent participant compliance submit –sd-id=<abcd>\ngx-agent participant self-description verify –sd-file=self-description.json\ngx-agent participant compliance status –sd-id=<abcd>\ngx-agent ecosystem add –name=FMA –ecosystem-url=https://compliance.future-mobility-alliance.org\ngx-agent participant ecosystem submit  --ecosystem=FMA –sd-id=<abcd> --compliance-id=<efgh>\ngx-agent participant ecosystem submit  --ecosystem-url=https://compliance.future-mobility-alliance.org –sd-id=<abcd> --compliance-id=<efgh>\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.1-next.20","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-qhc+8iRmFFKejZfIFHBUtdRwIjvuizfij02cc1qYb/GhguqNXVHHGHy3RZuxKh05wRvmZXsDZOQSdKYneJOHTQ==","shasum":"87b3e99ae6f34b463e779b70638578a2f9dab81f","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.1-next.20.tgz","fileCount":48,"unpackedSize":285989,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFCHR3AojWa3JslOXbS2KKUrZYtDP29oFBGRzNSUSOn3AiBX9JWyLN+yFiaAT/knfcuDgTwm5gP3RG2rqh3LX7uE5w=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjzpXFACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmos9g//bXrgy8YWr2uszmxjOI+Ce2npp3hTHWeWAiJqB7YBgs337OY/\r\n066S4cHVWu3n2DnGvI0nIdW40YLv0HKhqgLQ1lZbR0T8x2zDNuaUEmBHUBQ2\r\naJdIyQ97tuIvGH/0LdCCOhHVfgqGPqAZBQbH2cLdqh/hkHph7snSo8Qg88z2\r\nEqf4+Nb/+iRBmqxI49tb9orBpHYZg8OxL/6qTALeP0x4cAjQqwnvpMXTzpWJ\r\nPf00suGVBGiVmJJDRSiCh/vSPehjF0k1JY1mR8ud6WN0wjl/C+MrWY8ixdH4\r\nNUE0ZeTptdMrju0J3co4dWd7umRhLN+tONSAG2TgkhSUyYyXWmKcb7s1FmjB\r\nCjb9rAhKDp/oqaXbEYVRjNfLdKy1ku0F8pglN7gV444pVS4cIGnnAKzY2Ur4\r\nVDfWXIb9G1s02zk9o34DFhUaTx/+JYf7lvYXRXcIIuENIeTisLwV+PHZVZ46\r\nPvUPsLN9/xCKmRV/drzQGKaWzL6sz6996BLrhDk2ug5ekcpncWp47N+5rcLp\r\n9vXQDEFbPK/ANXj5iqNRdt2KXsr264sBz5zxUxogwykO8c0jEjXSo/Lwq9KV\r\nlfMUozwFo2Xgg8LknPnT4ay+pruCMZj6Rih/FCia4h3t5hmuUIsEOYBINzab\r\nuEvsnTWcWbxktJDRh5iw4kqVyMisDr35MR4=\r\n=oT8d\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.1-next.20_1674483141270_0.8620409563849247"},"_hasShrinkwrap":false},"0.1.1-next.22":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.1-next.22","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.1-next.22+985e336","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"985e33683e6dd3412aa1d842a2cdb48432e8fc59","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n\n# Prerequisites and installation\n\n## NodeJS version 16\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following page: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions. Type in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n````shell\nyarn global add @sphereon/gx-agent-cli\n````\n\n## Check that the CLI is available to you\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain=path/to/cacerts.pem --domain=example.com\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-compliance.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-compliance.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-compliance.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-compliance.eu.ngrok.io │      did.json │      ./my-export/nk-gx-compliance.eu.ngrok.io/.well-known/did.json │\n│ did:web:nk-gx-compliance.eu.ngrok.io │ fullchain.pem │ ./my-export/nk-gx-compliance.eu.ngrok.io/.well-known/fullchain.pem │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-compliance.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n````shell\ngx-agent did delete did:web:nk-gx-compliance.eu.ngrok.io\n````\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example self-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n````shell\ngx-agent participant sd export-example --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-compliance.eu.ngrok.io │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n  \"id\": \"be284e34-665e-4759-b2f0-4e9af6b9f742\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-compliance.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"https://participant\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"localCode\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"FR\",\n      \"gx-participant:addressCode\": \"FR-HDF\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"FR\",\n      \"gx-participant:addressCode\": \"FR-HDF\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n````\n\n\n\n\n```shell\n\ngx-agent participant compliance submit –sd-file=self-description.json\ngx-agent participant self-description create –sd-file=self-description.json\ngx-agent participant compliance submit –sd-id=<abcd>\ngx-agent participant self-description verify –sd-file=self-description.json\ngx-agent participant compliance status –sd-id=<abcd>\ngx-agent ecosystem add –name=FMA –ecosystem-url=https://compliance.future-mobility-alliance.org\ngx-agent participant ecosystem submit  --ecosystem=FMA –sd-id=<abcd> --compliance-id=<efgh>\ngx-agent participant ecosystem submit  --ecosystem-url=https://compliance.future-mobility-alliance.org –sd-id=<abcd> --compliance-id=<efgh>\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.1-next.22","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-E43Ldsqvf59Anb/oyZ7X8XCCQ0CTr5LjW9xHu4e8LbKfp6p1+h12ka+Hw8JybSU3FbC164b9vYGlxjfTxqbyXA==","shasum":"6e73cbc23b47f6287f7356b57b3280fbbb771974","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.1-next.22.tgz","fileCount":48,"unpackedSize":287133,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIAuGbjodMJ4qSAYwYrVr3Jgdq+l8X/MmVUL4llGJ7W4pAiBYIg35eY+3ccTJFAfEC13PzfjeK6xOpvHpewUIEyI7uA=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjzp4eACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoQ6g/9FIWrPlCb11vDIPL1rfXpG8XOCQTkoyY0d9bhIreDr1KCDXWv\r\nRis8R5JOA4Mt0rhbSX1EISaheHUtvfUvRpOpzzqn7Y/qGL9EqwZqKeoMCY2i\r\n0lIjqalBmmfr7knohpz4ffVF/6keeNGRqOl7RmksvyW7EAZSyOV8eUZjilqB\r\nnvXVfQh+14rurDjELjDjBBqjxbhwh1ujYkLMphcqoX7qbALkXIyj7rfNI+ut\r\nRTuaNJLf0qcP7bgukewC6aQGK7NIitmcn6XvTuE11YjCygEUgy516ztbQHau\r\npYAhx1Fbr6NPX7on3ILHP5hPcwnWM70urhrpEh3TOg6Sms3DwSKNPweMM4MX\r\nKam37FxXE/4ltWPBLJvBMs/1JjbSAZ7kSaqOrhOeBew/peRyK86vGXzIHT9w\r\n5wgVLXHnx+JT4hYHRoHsCqGlY+4ENIiSPIwfht+eHiFdwjv5JqWk6eHFaOrK\r\niJCbv/T3ppusX6f36PJN4EyY9/F5dFffYPJn6BASNtzu0x5l6Q4y2d8L+Q6o\r\nWsPUHYpYUiDAe4YegLFg7ZhpNKqOP6fF1LRN6NPtvwCL6uIUCtUyzB+bzNEM\r\nRfXYIPFiLITKSXFuE9rPWfE+gdj3C2pn+DhVtr4quMaP3j4M+S0uiMa5ZBXh\r\nYjSzXz77u58WCuI7njKHGs+nq4rzsrxpSR8=\r\n=DHoF\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.1-next.22_1674485278211_0.3901320347550832"},"_hasShrinkwrap":false},"0.1.1":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.1","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.1","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"f9cc2a1df105a219b1fe3a73af851297182d5561","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.1","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-HvjJimluvjsagi6Q4NrVUrVqem3C2RuXfWS1kiwBbeJV5glMtXdJcPF5lJ94Zb+zbEF9pKDNlStptx/BZ7buew==","shasum":"706bdefaba4876ca61f5e6e9cded2e3783bd7754","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.1.tgz","fileCount":48,"unpackedSize":287101,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIB/1VicH1ikxrGjXMe52cpZHjLbdrxDp4YUxRmcfvuNwAiEA6RTNzdPhxQCmPGNxKNMkpud6kT11OGtAUt/MJ8d4NZ4="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJjztChACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmplbg//W7AavnLMhEHQ126DkXCZejj4ZUXpf9F9JKi9R3Be5qg2lOpm\r\nFSXG7Mr3n0am+diHSQHjjky/FYELN/p/esWw6MCB6FuMcu/Bd5HdznhrJbCb\r\nYG2P6/Tp8YiVyM8xPJ2eRAFBYjccMTxEwRoqe4/8QVk1SRRY4vRWqIZ2bm69\r\nnCN8mb+2R1oQ79Lz4RuS1IheSV5AsZHERJ6RpBVQ4iicH9FTo6Fb5Zft3Gqu\r\nQrhPXCyC3nJeJyvfktDWth+WkfBN2gW5U+VSS9lty5bPfBBjmOgbTSGrLDqO\r\n0FkxbB506Xs40DrGjRwkEEmwf5muXE3aK4X4flpzFIGdGWpyrgblOkvECeYj\r\nShrUxLZ0FRtIbp3eFhSmLTR94Fkdx0F4TYdsaOVleC0fRF6y+cHpmiORlcK6\r\nBh6DZBsIFa/cJ5bN8U1plDzWqgQVKIh7qYoEHLSYor4NgQWMSVjJaoiY/cVe\r\noMdJIwpEreAmISI5ypXhVrhHKt2hUdpDbQB/wA5DpraZMt/HCbCO4/fugDfQ\r\n+plckqqpiVk/DMRLET3iNwHr7wcPzGwSnHWYFY5DcMUM/cAY7opsUHwYl4GH\r\nOYjWz+pSwYDOKzupAg61moLO/61RdwCkIcG4z0TEet6J+1rfHr7vJ6TO7mVO\r\nD3gHC7NvDLKGuZUak0nfZM3zIJ/nfDRGBzc=\r\n=9gWi\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.1_1674498209559_0.6834638050821202"},"_hasShrinkwrap":false},"0.1.2-next.5":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.2-next.5","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.2-next.5+c3daf1b","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"c3daf1b8762f0083ebd9af6a77709d4f34115a5c","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n````shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n````\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n````shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n  \nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n````\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n````json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n````\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n````shell\ngx-agent compliance sd submit -if ./participant-input-credential.json\n````\n\nor from an existing agent self-description credential:\n\n````shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n````\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n````shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n````\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n````shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"LegalPerson\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:04:58.179Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:04:58Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..PD6xomtqqHGnxFzCArJGesk5Qj4oOEE6nvQ_tPk7FuGRftECZvoh3CxXGPExNknienTINWLat6m83pqY_1GpC_pnsySrqEZaWVreXHQm8O2Gbp7l7duObAZafwxv05eCDRbg_Y-LoGi8ixyfPQGaFbuwIEDol_3xDbbIkV76YFlenygvf1mT9YL62qnhHgC8SOKyoUzlA\nslO3L-RhXDIi-BAas2oSkrYfOweG5FtiMqn91XZnXfpKxm3bkdieSuUK9-PQzrwQpU9HySSUe9yePgLK_q2EjlWLwY-QHTMGWzqcCiSpW3DgWgG6JgIiHdWxDqTv54Ot6ap0BJ4QY9MDA\"\n  }\n}\n````\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n````shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n````\n\n\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to create a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offer self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so sd export-example --show\n\noutput:\n┌──────────────────┬────────────────────────────────────────┬─────────────────────────────────┐\n│             type │                                sd-file │                             did │\n├──────────────────┼────────────────────────────────────────┼─────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴─────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"ServiceOffering\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n````shell\ngx-agent  so sd submit -sif ./service-offering-input-credential.json\n\n\n````\n\nor from an existing agent self-description credential:\n\n````shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n````\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n````shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n````\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n````shell\ngx-agent sd sd show so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n````\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n````shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n````\n\n```shell\ngx-agent ecosystem add –name=FMA –ecosystem-url=https://compliance.future-mobility-alliance.org\ngx-agent participant ecosystem submit  --ecosystem=FMA –sd-id=<abcd> --compliance-id=<efgh>\ngx-agent participant ecosystem submit  --ecosystem-url=https://compliance.future-mobility-alliance.org –sd-id=<abcd> --compliance-id=<efgh>\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.2-next.5","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-eci8e+2xqucfdCDQidRmAtH+jPwX+ii6zTEmxYAQScQvkwsOxB6aJgeHQyocP/5EUMSHe+W7G/E2AfQrlLCAew==","shasum":"487c2784e55f7576dce545c07507b0db2868acfa","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.2-next.5.tgz","fileCount":47,"unpackedSize":308165,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDuSOaZGNfQmgu7ic09orkQiTgr0yNZKpgGgs/5EtjXjAiBx/UKjbZ3S0d/rQczLrOi1u3BcFRyTz+mY3fWqWBoO8g=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj0jzdACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo6+Q/8DCSOhA23ereu5h25VrDwCTXAkEJlx2paacKYJH1TQRjRoOez\r\nW0WiUZjdjvat9eTJENGplrsE17uDgKpUm5z0UvONODeHwM67YvaFtFQwgKCm\r\nOljBpWpr1P5L60Dia4Rpla/icMM+m3yXlVDsIymIn6+g2vQbCetNqZPR9cgF\r\ndgzYiTrHRfdRnifMNSoSi4iC0lx5M7YOUz9GgNQrruggdVdZY8Lme5fWKJGd\r\nHfvg2DUA4y4mUF7cL2vd4Kq9Rj2m/diPUa4tIcNfiAtrKcU5onV0Wd+ZJstM\r\nP5zIvIaRdRomOaHxk7LXmJm7I/wGFIvmptu3Pxm65swjeMhFlJNQQ6QiFhz9\r\nJCxe0mfqJSX9BlPNQiX1Lsta8fDcNVQIO05JYs+f9mMy5iv7eXL/tWKSgJbz\r\np1W9vU5qdNeHfX0g8Tgg/DUsul91o5Emk0Fd60LeIPQv+PIzGWoMtBvB77GT\r\nd0v697wvEzc76u2qH9+SimS7PBzwutZt1WK70R27XS09JLkRiG0cjmOtJfEw\r\nCxzY+2+O/c1Gm0pWSwYtIVWW8Xn02u9nY8oBCmWYXZu5OR46pMcIGcC6ngbS\r\n8mTyvYOaASL1jfyOIwITvul0LlTuZyppoUp7rC87Y0JymAraCyJ14zAQIPYk\r\nKjH2emKxwp1UEDsnZp6m0f87OUyaOXf0YS4=\r\n=j+yf\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.2-next.5_1674722525676_0.4231974350732215"},"_hasShrinkwrap":false},"0.1.2":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.2","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.2","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"a2cfb2e99d304420f9562e884c68450c06bceedd","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.2","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-SUoXlskQbVTjSnMJuuxpLQAjrGn5E/ZMgieDPJCBf00fbU+Tu8qejYn6EnZBny86RiFEby9Entlr7NcRVjztKw==","shasum":"cf3a892610015e959da70c424df636ccd914d9a9","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.2.tgz","fileCount":47,"unpackedSize":308135,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICOo0FRQxSj4vWD7DeSSm0XY0VTIHwLyjx0yKc3lQuKFAiEAijPAc87xrsco4jTuGfbPGO9ygg3xdIet5UF5sbInwLo="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj0j1yACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqNsBAAhMEWQ7XgasQCZCauVwiW5TLj4uFtERn0zBr/qQe0A12p9ubD\r\nJ6E2dwKDFdd3YNxcqocH3WWVE1fnVmUqynvBWP+iWuC53DViTsF5Qrs2uL3o\r\npGjfeJu9V75xH1twOlrzraPe8tjenvQUabekehJ8fiVwAXzu7Z1CRsjflmcm\r\nm0OdYp2UhjKgP7v/Ji0Lpeudzi1GKKsHuvXlIWkhqAvZwa0KW9ItSe1St5nW\r\nvGnIuKdlgVX0+jvb4yPc0E2/uMJLVEZG22dUWCq6ukfGOKmm4OiwJDJ38H6q\r\nptmvE37z7f/4V+VQXUWKZ1MQx4bwW6902Pp52bIl+O5LB98RRii83gVOezfh\r\nxDqCyXXgb6eLdCAnbzBMOXOhV+iXnn0wJg4uze7lCf1xzql98L8lGjcw7HbL\r\necY6N6wGQsO4o3PHoD2pNu0NHXTuxWm440uxF9J6VFNNc8JKDcUxsuE1Ihh0\r\nk3TeIRYGaRdOVQAjt0nia7D63DnN2PcrcYrYndDN/k+5kvAQHvqK1QJVMfUk\r\n4bSCw4tTd7vd6I5tCps4xzkUfJqXYm9CHBrTxkSzDhiYChrkiqAorLXpvqP0\r\ndcM3B7qaKKtf92dbg5bdLpWucSsF4mLjVwMQLxwgagHhku/tcj1waZCM4hRX\r\nq4JQm76AR1QWufiIsLXz4wy6UtADOUpvnNc=\r\n=P38p\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.2_1674722674402_0.6126710384960024"},"_hasShrinkwrap":false},"0.1.3-next.5":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.3-next.5","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.3-next.5+1ecca76","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"1ecca76c80738fa4d269c200ac91f02d4c443c5d","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"LegalPerson\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:04:58.179Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:04:58Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..PD6xomtqqHGnxFzCArJGesk5Qj4oOEE6nvQ_tPk7FuGRftECZvoh3CxXGPExNknienTINWLat6m83pqY_1GpC_pnsySrqEZaWVreXHQm8O2Gbp7l7duObAZafwxv05eCDRbg_Y-LoGi8ixyfPQGaFbuwIEDol_3xDbbIkV76YFlenygvf1mT9YL62qnhHgC8SOKyoUzlA\nslO3L-RhXDIi-BAas2oSkrYfOweG5FtiMqn91XZnXfpKxm3bkdieSuUK9-PQzrwQpU9HySSUe9yePgLK_q2EjlWLwY-QHTMGWzqcCiSpW3DgWgG6JgIiHdWxDqTv54Ot6ap0BJ4QY9MDA\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to create a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offer self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so sd export-example --show\n\noutput:\n┌──────────────────┬────────────────────────────────────────┬─────────────────────────────────┐\n│             type │                                sd-file │                             did │\n├──────────────────┼────────────────────────────────────────┼─────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴─────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"ServiceOffering\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n```shell\ngx-agent ecosystem add –name=FMA –ecosystem-url=https://compliance.future-mobility-alliance.org\ngx-agent participant ecosystem submit  --ecosystem=FMA –sd-id=<abcd> --compliance-id=<efgh>\ngx-agent participant ecosystem submit  --ecosystem-url=https://compliance.future-mobility-alliance.org –sd-id=<abcd> --compliance-id=<efgh>\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.3-next.5","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-vRf72Qg3a28XammPo5VNkmwb5S8cuo8e0YFWKsr0TlyE3dr6H8ol41T6W77aTQUZtvl9caX9ngSnnxhkE7Rshg==","shasum":"1bf85480806c3d16d305a3933e8322efb0c55afc","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.3-next.5.tgz","fileCount":47,"unpackedSize":308185,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGSlP4fyrOVxUoOXNUIKSuCerfthXofo7Jy66qRmw0TLAiB40A4aAER5XE5U2Z5T+fgVxTMMOov9K5IhrQuCF3HOhg=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj0n5UACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmop0g//UetS9+hIIg1yOdQHun+j5Q8F/3DzdS/HCwHfUxQTqqQOjLxk\r\nMCE0IoMcozhPI6b2T67UIvACTRGjceay8drs9jzvYvxsid5G2VxWOwS4B2sv\r\nL4duHQztjNyIPf8CzcEzXJBcwlw+2NNXvYU0xxWDAc4S+SLlxd8iv0X5u/3D\r\nK43mCepPPCtVQGxkLBDm3utM41iqykU8sIekTzYS2WrO5vEvfzWOXm19uPPI\r\nKilWNRx5qnFtrt+ONNLOt6g/wI7QtkpkpzZYhaJeEPDUhBTKScCV6mYsms1o\r\nhLP8yEsC7recM+d1A1X8U4Ndirvo7GcKxOFjw95L07lwTCFjlxjLgnPftARv\r\nBJn3L3pCftdTMAmvglGFD5pBjuGCjGreExrnG9A6g2v4S8ca4dl7CxrzcW1N\r\n41oNWj/t1mZOKftrE+Y9TCqfS/C4TNYmon4K/mW4qxh4KEwHxRf0XN4ocLCK\r\n0/EQasQ6fs+8Y0dnrh1rQp3dnMxjAAH9tSzzCMxXM+iiTYY64Y5r9NVMah9e\r\neAq+fldF/s6yu/1WuPb6YXkaxHmjyFR5cH+cW2EAHLTmtBsPCxXb0U7p35Xk\r\n+LlxYS7Iw3UoLrtP19iA10mfz2Dg8w54DLhI2aeCmyJ+y1GKR+mHg4/fRDSy\r\nEAgIHYUN1E3yKCw795A8MqBZsvAK7KwvSBY=\r\n=Lg8m\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.3-next.5_1674739283978_0.4758555912706772"},"_hasShrinkwrap":false},"0.1.3-next.8":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.3-next.8","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.3-next.8+5e66c77","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"5e66c774695f931b2b71e448f0192117e930515d","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"LegalPerson\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:04:58.179Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:04:58Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..PD6xomtqqHGnxFzCArJGesk5Qj4oOEE6nvQ_tPk7FuGRftECZvoh3CxXGPExNknienTINWLat6m83pqY_1GpC_pnsySrqEZaWVreXHQm8O2Gbp7l7duObAZafwxv05eCDRbg_Y-LoGi8ixyfPQGaFbuwIEDol_3xDbbIkV76YFlenygvf1mT9YL62qnhHgC8SOKyoUzlA\nslO3L-RhXDIi-BAas2oSkrYfOweG5FtiMqn91XZnXfpKxm3bkdieSuUK9-PQzrwQpU9HySSUe9yePgLK_q2EjlWLwY-QHTMGWzqcCiSpW3DgWgG6JgIiHdWxDqTv54Ot6ap0BJ4QY9MDA\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to create a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offer self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so sd export-example --show\n\noutput:\n┌──────────────────┬────────────────────────────────────────┬─────────────────────────────────┐\n│             type │                                sd-file │                             did │\n├──────────────────┼────────────────────────────────────────┼─────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴─────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"ServiceOffering\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n```shell\ngx-agent ecosystem add –name=FMA –ecosystem-url=https://compliance.future-mobility-alliance.org\ngx-agent participant ecosystem submit  --ecosystem=FMA –sd-id=<abcd> --compliance-id=<efgh>\ngx-agent participant ecosystem submit  --ecosystem-url=https://compliance.future-mobility-alliance.org –sd-id=<abcd> --compliance-id=<efgh>\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.3-next.8","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-bSw9UZqCAV6Swc8v77O72muJFEN1MyY2cAow8Pkbv5x/Yh9k+Gziq2pgD15W9x63w0JtI3QnJuEcS0LGrdWb8g==","shasum":"7e0949c3d8769b2c12e783257682b8988847cc7e","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.3-next.8.tgz","fileCount":47,"unpackedSize":313217,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIHTCG9BDcrPEGf0nWJP5J7W0rV2xlvU7Otx8wBNSBXzkAiEAnPpUCBAiOGZkT6hxCkLTgaxDbeNkJjr9mArYkZe3U8A="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj0ppPACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoYcxAAoIA/YWjDhoDSekoQ8kW0HOI1rIwmM41CffoDC+79REI9Wz8w\r\n7oBLHZTRLgBRiO4Jr2d4wMhsg/Xw3v6bb09+SM0AbcePNalrXuGanhejezEC\r\na46vm2BwEh/BV3fSL6xIyHq9tbEWkSA3w6Nvu8yhezh3n9+j5ML0tAB88tkh\r\nJHiwRUxNPG6gB1bfAEkdnht/utJO0zPW0S+WDqEi4DCBlYZ91zgIFA0hAc7p\r\n7kENbpDhkL+FebwDpXX7IVdKkR41lotn9Ct2QvqwtssNfrkaqV90BJBIOeG6\r\nc4NdjZ3oMa5/7CsceGUO6jbFJzN8RiiBnH6eRYXVAEcstaJXO/8bjg6yJDJ3\r\n1BQUBu7VU5VSq1DHfK+CkxEyKvGbR5DaFUUQT2p5L1tEABhaAc60k2UXSmCL\r\nUEW1SLzcyK6L6HjDruJ31cbxu5aezzzz9oHKSmSpgGB7UuBOLBacmFaKn0fu\r\n+iaqCFnbeBN7z1IfoDsR5OAVQm8uYvVHfHliyHgHrZcESf6+zRqleqeUFqD+\r\naaxaisYRRHPO7VOozZBBzwl9VwJCExL3pH0rZlsvnHZHQEahOo2ZgO8KG4Nc\r\nwKdXIYx2qw2Vo7kA5EO/f63X00AXuaRST/Ttql9Bru/+r8AAWyNcBTw7IfOD\r\nojUV4JMU5Fxabab3BqP/pAaDuVHlnSXlE+A=\r\n=JL2C\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.3-next.8_1674746447485_0.31389607325078495"},"_hasShrinkwrap":false},"0.1.3-next.9":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.3-next.9","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.3-next.9+00d5292","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"00d52921457d637befc69f54bcd50aa96e78f7a7","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"LegalPerson\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:04:58.179Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:04:58Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..PD6xomtqqHGnxFzCArJGesk5Qj4oOEE6nvQ_tPk7FuGRftECZvoh3CxXGPExNknienTINWLat6m83pqY_1GpC_pnsySrqEZaWVreXHQm8O2Gbp7l7duObAZafwxv05eCDRbg_Y-LoGi8ixyfPQGaFbuwIEDol_3xDbbIkV76YFlenygvf1mT9YL62qnhHgC8SOKyoUzlA\nslO3L-RhXDIi-BAas2oSkrYfOweG5FtiMqn91XZnXfpKxm3bkdieSuUK9-PQzrwQpU9HySSUe9yePgLK_q2EjlWLwY-QHTMGWzqcCiSpW3DgWgG6JgIiHdWxDqTv54Ot6ap0BJ4QY9MDA\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n \n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offer self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so sd export-example --show\n\noutput:\n┌──────────────────┬────────────────────────────────────────┬─────────────────────────────────┐\n│             type │                                sd-file │                             did │\n├──────────────────┼────────────────────────────────────────┼─────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴─────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"ServiceOffering\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n```shell\ngx-agent ecosystem add –name=FMA –ecosystem-url=https://compliance.future-mobility-alliance.org\ngx-agent participant ecosystem submit  --ecosystem=FMA –sd-id=<abcd> --compliance-id=<efgh>\ngx-agent participant ecosystem submit  --ecosystem-url=https://compliance.future-mobility-alliance.org –sd-id=<abcd> --compliance-id=<efgh>\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.3-next.9","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-ypdnBI5/Wkz1NH9p4BuXQ/zHlW4oeFKiFXweeH4xWYJ8cCp7qkzHMZ6sXFhuu0WZF9/P3O78qK13PkKf15kmUw==","shasum":"dbd70a6b8d819e501f6f4ca86bd4ad1f6a9b04fd","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.3-next.9.tgz","fileCount":47,"unpackedSize":318097,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCKbR30Ewi8xMpmOXRykOri44ikaIbOAU6/e8GuJJb5cgIhAJGxuvgAxS1I4B3MlNIGVy/HnKpL6jrPmBkFDdHcVodb"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj0qM7ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqyiRAAhjEADgWCndj9FutM1i8Iw4pwI8b+KTRP+qqdN5A3ThDgmCrX\r\nsZmXYIKdHwHrzpCKFg23ga/dPz9QuOjhSaedsK4KoD//SH2tuGRbW0HzXLw/\r\nIoowuBFAqbcD/25SHj+MegHJDa05ofvq9Qwm/WymjdloWOZzfY530Co27i8g\r\nKBa3IAOA84R+xSLaJyqSj4EJelZIz+HXkKpdxApCkiUi3KMw4R18mI77XaHF\r\nb/NejD6ADCpejHKRklwEqMwLRlSMqzCCqnpv3gRqYmfxlamU2lUAuLTMbfVE\r\nv9dpH+ClKZGVYCxI4KCDOMhBAPQZdc3pUPV7+a19ObToaAphWMtmxdwDYAXI\r\nAOt4cMaSKQ01zAdvpezBNGfksmxyK2Mfg4kSFOdHIjV0MkgsSNHpoDRjMS0d\r\nRe7PRQ0HtAhYUINV63e5uE2Tx+W6BogQX7ek0euWPOHM48p1NaMwACrkk8fj\r\nke5XBEKyza+Gmp89ylyfr8L9gChI/nlHFfH2nll5+EdRKDVg+xhG6mVnLMkE\r\na/7iqvzA63zWXCePidtVevSnQJvRv9IuwKITA20Nh9Zyycgpwh0FkoaJP400\r\ndwyZhLZUNPsN2/JmxlfeIsDsD/9R2jNA8tvfhG15G9cXh7IQYsypiJL5851S\r\nEHmgZa3gT/sHD9/5GtjUZ4dlZIKlQw6O53E=\r\n=84Pc\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.3-next.9_1674748730882_0.41513284375911397"},"_hasShrinkwrap":false},"0.1.3-next.10":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.3-next.10","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.3-next.10+8c8523e","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"8c8523ed3d373e8256def165e154f583cd6400df","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"LegalPerson\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:04:58.179Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:04:58Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..PD6xomtqqHGnxFzCArJGesk5Qj4oOEE6nvQ_tPk7FuGRftECZvoh3CxXGPExNknienTINWLat6m83pqY_1GpC_pnsySrqEZaWVreXHQm8O2Gbp7l7duObAZafwxv05eCDRbg_Y-LoGi8ixyfPQGaFbuwIEDol_3xDbbIkV76YFlenygvf1mT9YL62qnhHgC8SOKyoUzlA\nslO3L-RhXDIi-BAas2oSkrYfOweG5FtiMqn91XZnXfpKxm3bkdieSuUK9-PQzrwQpU9HySSUe9yePgLK_q2EjlWLwY-QHTMGWzqcCiSpW3DgWgG6JgIiHdWxDqTv54Ot6ap0BJ4QY9MDA\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n \n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offer self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so sd export-example --show\n\noutput:\n┌──────────────────┬────────────────────────────────────────┬─────────────────────────────────┐\n│             type │                                sd-file │                             did │\n├──────────────────┼────────────────────────────────────────┼─────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴─────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"ServiceOffering\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.3-next.10","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-RUUwQb+lk/41k1BMpmw0wnwftqqHPAlUmOxsmyMBoCWhFz8AcQOWyTkiIYd7FZlrj9VrDJyvTyCW8JtFCQvrAA==","shasum":"d9887f61317188b0c78c264899832e18db4c8511","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.3-next.10.tgz","fileCount":47,"unpackedSize":317749,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIE/OyIycckBGx13c4m0BAvoKkTsnH7N63VV7hsBnm36jAiEA2rs7loD6JxB6iFICst8zP3rd6bwKBSHLcDy9nOIdegk="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj0qWVACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp0zg//aat7d0E9pX1fyVTVfIzV+YX1MSHPjB01BDTBA+vm2GTqoSeo\r\nQjjhqmBfA0HClYqhZx4w0Rt5CMGuUVrwraZ9Vg8L+NrBOclbo9o/KVdkbWMM\r\nXgOyMVhdVlgpBoKI+h/FMiZ3d0T60ziSdnvWOvEawCqZJUP56X6LQ5xxVl/R\r\nKT8tWq9+cgwjmM1WIJoXFVNAfCzYfRu7sK6PbJZXmerq0yn8Fzha0G72Fm01\r\nKLtElInJ3hD7+f9ohyUeZM/u2WZHWe0da5P5d7RfC+1dzFSAWJ/8gg2B1RlR\r\nW1SqljuIQ8B4DgLIYmNYpHQPZx4lCieIFtGpTdXRlIOoS42DMqhstRVE5oyA\r\nF12p0UBPHoBahXVHb0yGCJb2AY9/Z1O2e+GGROQvLfjFlT+UAfPUw0FiZSvZ\r\nVJFTzSY05joEBM5rebDLX1fFL2mEiveF2knLmpd+Yn+hf1HZ4lrCYW8guSLl\r\nxFt8tzJ6cAikna7bZ/tzprDnrm8N/Wpd16E05odK+ewRpZaJxVMj5bzzbtiL\r\nXMnaMyQA0rTmQu6Tt7pwjUyfKbSQz/20qOE6lMGrxKiiO6l6Ej2hRWxdGyzH\r\nQHDX0gLCiZ5KIqIzuGnwOzbURwgMMEhgs2Ln8zRuN4Mxct6Hwx6HcjBrqsve\r\nQYfpv5EjnJbX44liqrHjl85H9er7XoYVVQc=\r\n=meIb\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.3-next.10_1674749333393_0.14530049386154031"},"_hasShrinkwrap":false},"0.1.3-next.11":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.3-next.11","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.3-next.11+7c31905","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"7c319054930f1264a4f972021486169a86127e15","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"LegalPerson\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:04:58.179Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:04:58Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..PD6xomtqqHGnxFzCArJGesk5Qj4oOEE6nvQ_tPk7FuGRftECZvoh3CxXGPExNknienTINWLat6m83pqY_1GpC_pnsySrqEZaWVreXHQm8O2Gbp7l7duObAZafwxv05eCDRbg_Y-LoGi8ixyfPQGaFbuwIEDol_3xDbbIkV76YFlenygvf1mT9YL62qnhHgC8SOKyoUzlA\nslO3L-RhXDIi-BAas2oSkrYfOweG5FtiMqn91XZnXfpKxm3bkdieSuUK9-PQzrwQpU9HySSUe9yePgLK_q2EjlWLwY-QHTMGWzqcCiSpW3DgWgG6JgIiHdWxDqTv54Ot6ap0BJ4QY9MDA\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offer self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so sd export-example --show\n\noutput:\n┌──────────────────┬────────────────────────────────────────┬─────────────────────────────────┐\n│             type │                                sd-file │                             did │\n├──────────────────┼────────────────────────────────────────┼─────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴─────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"ServiceOffering\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.3-next.11","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-g28wG9myII1hhkGojX06cT/Kt+B5G1jMcT0bAliC6hz1/TZld/SBlaRmWWplDALqDYcCHOdGx11Yz7mf9tZSNA==","shasum":"4d78289bd7928062e348943d41e625b795a422c1","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.3-next.11.tgz","fileCount":47,"unpackedSize":317572,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCBj7Y1F64ildLWxZnVzF7zKSk8F9iY7fjNehvbIG9X6gIhAOL8E6mmJdaHQ5ghMqhtoDuEgHeEVDI40zj8yKqqTCLe"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj01GSACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmorew//SBm2MiCXsjBWf97Z8/6ApYZtm1joymhPsCoz9KKm9eDBqAAe\r\nWNJIP6FX8NBcOH54FQ8uG5Avu/+VYfYtcHDMhI2m2LpjVnYQRNstKFXtJm/u\r\n8rMVETd9fyJV/bURC/u7cvsujCKKWKc46lCNv6AOT4z0sO9vR9kv+AoPkRta\r\nv7GGyprd33QRhLTYNlomqIjLlsbNb6TEWkH3MOtWOMnAEx6H+49mP318WZZn\r\nPoyNtRaIZLzJcgQVjYZ1oLVYz3v+WHEi6fm++ypjcz/D8v3n8+92fNDxot/5\r\nnoKCmjLwFOoFXeeRar8ElhQl6fuWaJG10YsZMqgdsoHrZstl3J9FX6eWxoIa\r\nr+1KzuueLRs71ZocCxLHk9XE5AN3mZDEySV+/al39QSxaiJXH4UbPNPgoSSj\r\nfGcFqOska+8L2f2T8QTJbQ42kVBG2sozM62Cdr4LtAC3J4t0mjrcwpEkFRuP\r\nhzSb33rbwviyyw1REDESp4SZUC3dnykJrwZKRp6z5Sm7Y5ohEsNl+C38B8PS\r\nC1l15qDIXLmj3WMaNmFV8LoV+NNnPXRCYKDRz0hw65qOM0XOibKly3nV7Lhn\r\neDkFL+Ole3nz6cTnMEcyBwTJ5iAHhmK45f4rxDehmNfvnIkzuS4N59OeFNLf\r\npJWvqg9U9H3PLOVEhxQYfra5fFVexQpDXDc=\r\n=9g5r\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.3-next.11_1674793361826_0.044897659685841695"},"_hasShrinkwrap":false},"0.1.3-next.12":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.3-next.12","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.3-next.12+c6f2193","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"c6f2193eee408498a6f684febf9aea2d2c0b08a9","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"LegalPerson\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:04:58.179Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:04:58Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..PD6xomtqqHGnxFzCArJGesk5Qj4oOEE6nvQ_tPk7FuGRftECZvoh3CxXGPExNknienTINWLat6m83pqY_1GpC_pnsySrqEZaWVreXHQm8O2Gbp7l7duObAZafwxv05eCDRbg_Y-LoGi8ixyfPQGaFbuwIEDol_3xDbbIkV76YFlenygvf1mT9YL62qnhHgC8SOKyoUzlA\nslO3L-RhXDIi-BAas2oSkrYfOweG5FtiMqn91XZnXfpKxm3bkdieSuUK9-PQzrwQpU9HySSUe9yePgLK_q2EjlWLwY-QHTMGWzqcCiSpW3DgWgG6JgIiHdWxDqTv54Ot6ap0BJ4QY9MDA\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offer self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so sd export-example --show\n\noutput:\n┌──────────────────┬────────────────────────────────────────┬─────────────────────────────────┐\n│             type │                                sd-file │                             did │\n├──────────────────┼────────────────────────────────────────┼─────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴─────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"ServiceOffering\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.3-next.12","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-lVaFvN3U5Kq1CewzfdpvzGoUrThF5JvIMojdu7y1KdYdGkfDgZfvzse2oIRf6ySVKoVHkIjK/JQ44Su1aigY1g==","shasum":"f48c0d0ab14e57f29ccdf40c333b92e7f7ddabd5","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.3-next.12.tgz","fileCount":47,"unpackedSize":317572,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEMvWcYSuV93Z8WNcLZR9WzwnNEPOQCkfKafrnEjH8lUAiAFcvbmcXNTWN91iLClvjBuD/cZDjhy8Fup1+6vTmTfKw=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj01PbACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpJ2w/8DW+VGb/hO1dtP7KciHEU2dAWhJhTOMK79vF04lu4RwoyARG3\r\n+VmX/6r4snwYUVeZ5HJYO0CsYBpkZ6MaJk2M5pw2EdJ3umiLDCIZuO37aRGi\r\noshmlAETeHc6aSMILtDM2EhHyDd1wijbKPoUzldnKV0P/zoGbJahD105UpD/\r\nCJl2Sof0GxeNVRZuZe/q1Fw3cscZQI/2Jdwf9DGNg5I8qp0CL//6OZ/cdEWs\r\nccuQjoIkF+3d+A6YuLOisqUSnYZiPzHFnJVu+Dbam+Vm8HGQDd9j13uWgeXU\r\ngG/MNjUmTXN+iBSNo1slZ849Kwx/caewjYLA/KlV/gFnOvw+3iNLtJ9ljTUn\r\nIjnPNzhYVdYDhI9WEdP/YUMwNjOJn3MxMI9A7dlKQ7juf16tKq4b0CjiX1oE\r\newfAtlhABpnTmctu4NYGNZTML7lYP6pV5wxXjmePPyOv0u6XHO7UCuB4Nx07\r\noq9w2lsLJdM79xTO8eHTAT78vkNnx7VY/LXIl/AG5SWJPDoSyPOjdTgVXP5P\r\n1XU6TUQu5bRwMw7AwMT4B7tQgNwpHVcrsLwqSsdSCD7i4j3c1j07ZOLzKo4P\r\nVLmxLcqnmCnXEaPBO3clz2nzQzf8YDR//5QK6dZRE9QaW1SgCZnwv3jtwkPM\r\nmlo40hg7n+BitZkPNFVNwcPs5/EvIPaI3SI=\r\n=QG+Q\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.3-next.12_1674793947300_0.15324644127297216"},"_hasShrinkwrap":false},"0.1.3-next.15":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.3-next.15","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.3-next.15+da50fe6","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"da50fe625363f013da2f5b5b02fd71fb792d4743","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"LegalPerson\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:04:58.179Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:04:58Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..PD6xomtqqHGnxFzCArJGesk5Qj4oOEE6nvQ_tPk7FuGRftECZvoh3CxXGPExNknienTINWLat6m83pqY_1GpC_pnsySrqEZaWVreXHQm8O2Gbp7l7duObAZafwxv05eCDRbg_Y-LoGi8ixyfPQGaFbuwIEDol_3xDbbIkV76YFlenygvf1mT9YL62qnhHgC8SOKyoUzlA\nslO3L-RhXDIi-BAas2oSkrYfOweG5FtiMqn91XZnXfpKxm3bkdieSuUK9-PQzrwQpU9HySSUe9yePgLK_q2EjlWLwY-QHTMGWzqcCiSpW3DgWgG6JgIiHdWxDqTv54Ot6ap0BJ4QY9MDA\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offer self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so sd export-example --show\n\noutput:\n┌──────────────────┬────────────────────────────────────────┬─────────────────────────────────┐\n│             type │                                sd-file │                             did │\n├──────────────────┼────────────────────────────────────────┼─────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴─────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"ServiceOffering\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.3-next.15","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-S/FqopghPv4vd/zyCV3qD/OZs1dRhzgu9VtywfmaS8Oz9qYEnEQiUrOsk4kbQ9C2PX1zDL2Wtp72Vq8D0+otVw==","shasum":"38f1cc4cebbfc6ebec624b9fe619e9d46e68f74d","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.3-next.15.tgz","fileCount":47,"unpackedSize":320421,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCGyl+SJhlfCEhAohaXYo+asq0MgJlgi9P8vSWv371SHAIhAL7p3GFxl19LKfqHvk2n/5363L0elpAMyx4XXMHYHHLk"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj06rWACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoOjQ//eQQ3Zm3JxViJ0i2B4r929O6aKNsQ6ekF8h8NTL+JS1ERcl8S\r\nD8H9+vtlrZWwMe1jge8qaPxGLBVndffeKtpSLL24vhmNTtK9qOyW/JyI+3RU\r\nfuw6FwbnSAdEtv+TV5FGQTw+q6I9LcYXrmrIHVmctLSADaJU9pLaYLLBKHTF\r\n0V1ohYQ+OMian0ixx9SwvDiWUG6EU1W6vo9e9i7yWZn8PsJNcPPSvXQbHkV7\r\nlQit6bRPq9n1HswpljnD9+Ml2lmzZD7AH7dO3sat8XFV1Z8Y4U68QtcE05QV\r\n52B+r9vdmHKSshCM0oXi1SpwFsSVfKE89DQG5P5iuY/N+JaX7B2SuI/jogex\r\n3Lt1AlbZaTKKzkCGEoT8mdY0JG5wBbNXEmhowN5d4SqWInpyjPwAqeLKuh1U\r\nl8/bhpDPsvSbuzY9QhtAWF5BcYf6IqJ3HiJlHTtzBOXA9DMqczDkXbDgqFHc\r\nZNjk9m5ofwR1xl+btVeV+a4HiBzlMHCK9TziaQxrONdCeUxp5GzwSDW8DmN6\r\n2gBbgCTTEQEfKPh9/dxXOBZnfBRPx5bnwTNsHCieA4AwOBu7C/t5uErc1OlS\r\n9mdwK1gj4e9Gm3ZEa2uzza6fOiYjeDXb81OXLAcmB/q/DJTEPRdpsjAjFVAk\r\nGv3OTT1pEZY3zmMcqgoGlu9tyf/3gRSa7Vs=\r\n=VmlX\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.3-next.15_1674816214554_0.2902276500584824"},"_hasShrinkwrap":false},"0.1.3-next.16":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.1.3-next.16","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.1.3-next.16+6b69e3f","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"6b69e3fd54dacb1fed9a08fffab0f597a9dbce18","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"LegalPerson\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:04:58.179Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:04:58Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..PD6xomtqqHGnxFzCArJGesk5Qj4oOEE6nvQ_tPk7FuGRftECZvoh3CxXGPExNknienTINWLat6m83pqY_1GpC_pnsySrqEZaWVreXHQm8O2Gbp7l7duObAZafwxv05eCDRbg_Y-LoGi8ixyfPQGaFbuwIEDol_3xDbbIkV76YFlenygvf1mT9YL62qnhHgC8SOKyoUzlA\nslO3L-RhXDIi-BAas2oSkrYfOweG5FtiMqn91XZnXfpKxm3bkdieSuUK9-PQzrwQpU9HySSUe9yePgLK_q2EjlWLwY-QHTMGWzqcCiSpW3DgWgG6JgIiHdWxDqTv54Ot6ap0BJ4QY9MDA\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offer self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so sd export-example --show\n\noutput:\n┌──────────────────┬────────────────────────────────────────┬─────────────────────────────────┐\n│             type │                                sd-file │                             did │\n├──────────────────┼────────────────────────────────────────┼─────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴─────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"ServiceOffering\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.1.3-next.16","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-+UNYWkRxglaWTCITWKzddfGqiSNAYo4H0RCEVnpYadcwj4dOFvyzuvIE7i6ui80yDb0IV5pRXKVC3qc/dSZauQ==","shasum":"265184f2731a6f1501a7c14802da15f7bd268267","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.1.3-next.16.tgz","fileCount":47,"unpackedSize":320421,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQC/hIawm34kXM5glLnzETy433mr6aPcC28WMsy1BxLKEwIhAN1uiydJ/DZdQgM2qfFpcxr0aYkFyXZdRZWf3RvoKNT8"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj062gACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqw3w//f8EO5Kxc8VvMucBQCy2k9X99O0BrZAMkb5N6ueVoLY2VLBSe\r\nt0652SC2lIua+K1oT47uL+PF5gK1m57QeiaEGrddChomv8Fed9MgJrp6951t\r\nE4YPDGOpLmUWUOkpho/AfQUymb25x58a+KJRRRwweaVYjb9kKXvTHwEki+cf\r\n7VXH7X6PmoPy8l81QKrIT5tJ0CFsFGY15D1n/1NX8ut9VCVsiHwYs60ORrrv\r\nYMmfNOCdHhvrOF3Nz3RJgmJ44XS8Tm0JK0GYpmmbMqL7W9MkJmTYxIIj1vEI\r\nP03l+JakncgMS9s+Jzj609F1Kl58u1U9AZuvQuPVuph5s+JLCgDlJkZSxsjz\r\nNyHKRv6ctbAGiPdylY6XADTag/eBJcftFJpMe5EiIlJ65vH/ONtxDjFqcpH3\r\np+Xa3tnSOSAV98MVyvOfR1fn+gBwntJPzm1jIKLkpk32gVf/k2FTgE+q9kLO\r\n4FPPtZizb62Bxnsuvy4I0spS05E4UZP8gnt9C70Gtm4X3Qq+1gLUtaV/GJ2q\r\n/MjCk5cIbqVg/LwFuU+5W00fqq/UlKBPAk3v22EVkxrEkQo1hOx1s4G6WdIG\r\npLZDV46QHj6Hw9Wkts1aCpTsJTlvtiEP0Yrk8vgWrqGDvUN2C+9BjJohSVyW\r\nzIGdKrEvmyFU8d1ucw9N0ID6/kGI8yMuNEA=\r\n=buwR\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.1.3-next.16_1674816928314_0.5265610346669138"},"_hasShrinkwrap":false},"0.2.0":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.2.0","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.2.0","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"07c4bf2ffadd45468850d765a76a843c91934172","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.2.0","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-3/2uj1iYnCGQ4BVGSE18qTMfiF0A+BWHErT0uKpODKwDVGAjWb2NNor9R+OkDE1ZNl1Wphk/DEWyfmePjald0A==","shasum":"5c99f1c5c0186deb73519e81ed306465b92e0e42","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.2.0.tgz","fileCount":47,"unpackedSize":320389,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIG5RESsmr0bSBpBIZG4YXW7R9Zo+/CRcYMal1TFP18zOAiBZZwYqFh6nWrCWtDAeJ9bu/2t8klmwCDXdA8YK0nGrEw=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj064zACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqRjA/8DS3nhF3q5YlqrPQU5wjYBdUSEJ8sy0gv53T6uuVhhuQS3SuQ\r\nd/qwG7x9UVzhHJinM1mJTYqRXnxpPzokq8bdkQcmyBK+8GigdkRCLU3Dh5Gr\r\nMZ5B8ulVtYaSH6Ln8J1L8wOtp131KWsDKFoE1VBBLKwHfTmz7Vb+QchYSqEe\r\neL1v1APf9HiPTRhhtW3UsbfSk3xh0cWDpMcBFEns8uK0IW/wkviCTBGdT2gu\r\nAzwY2ik28jcmj1DqEP1RbAPcZciV3LWC6CG5pjSJYkgN9BnVZy2mlNE9BPPx\r\nlG8fMMK1aoTuDpLgyHZ7Pm5OOqdShNnKbVb+kUihh9q34ndA6gMm4if1rRO8\r\nfj1cstB37VDi7n8bjX2SGtv3nr/0lPpnApW0VcdXAz/y0lfXtrUMFu3ZixTe\r\nze74obdNnTjZ1oXQ3WKvAcGNJtAfhJAFX+CgoPnTSHmskODt12NQT2TnKbrn\r\nMPwJyPsZFN3U+GRYQXb+0+uipWJc88lageklXXFzM3oy29PgTldHCpmw72OH\r\nlBUd6tsZxu3ZcU3o1LqP/eEQtmjbBJl2JMirF97XywVp8EM7sIpWeLn6GDc9\r\nkB5uvWACTiTrVCtnSN4PkCNCp4A6JZLYvcasOCjAnQw0JaZAfBVzYmQYLQje\r\nbKSYzZgehja8PFwVdycPLg/FI/Z6ofs9F4A=\r\n=+fbP\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.2.0_1674817075065_0.4076124089495501"},"_hasShrinkwrap":false},"0.2.1-next.2":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.2.1-next.2","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.2.1-next.2+79060d0","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"79060d077b3f303ac74dcaac7b7063b33343e9d7","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"LegalPerson\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:04:58.179Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:04:58Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..PD6xomtqqHGnxFzCArJGesk5Qj4oOEE6nvQ_tPk7FuGRftECZvoh3CxXGPExNknienTINWLat6m83pqY_1GpC_pnsySrqEZaWVreXHQm8O2Gbp7l7duObAZafwxv05eCDRbg_Y-LoGi8ixyfPQGaFbuwIEDol_3xDbbIkV76YFlenygvf1mT9YL62qnhHgC8SOKyoUzlA\nslO3L-RhXDIi-BAas2oSkrYfOweG5FtiMqn91XZnXfpKxm3bkdieSuUK9-PQzrwQpU9HySSUe9yePgLK_q2EjlWLwY-QHTMGWzqcCiSpW3DgWgG6JgIiHdWxDqTv54Ot6ap0BJ4QY9MDA\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offer self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so sd export-example --show\n\noutput:\n┌──────────────────┬────────────────────────────────────────┬─────────────────────────────────┐\n│             type │                                sd-file │                             did │\n├──────────────────┼────────────────────────────────────────┼─────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴─────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"ServiceOffering\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.2.1-next.2","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-yLtNzOx1zx5AYX0CJW+pO6ugsd7OeuLtD7lfdqlkPMwXrRGgb5y9PbrnOVdImVQyViB1ovOseLto/an3rk4N0w==","shasum":"8a00d8eaf03673db6c522b33065cfe407e93ad8b","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.2.1-next.2.tgz","fileCount":47,"unpackedSize":320443,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDxg13Nju1qeDEurbp6d2NPN64NkGbbZyUSttgCG77RkAIhAKZfbAnrj/8y8A1Wt0axaDidRgApdYHN4j3sgrTJjhSO"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj07djACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmogaQ/6Aglcd/0G7sc4CoPfFvmBQAjdPIdS2I4fzCQi/KBm7a+LpIf4\r\nRQD0YqeVQZZLloKhywF3YL5NNnjN1j5CZ0wLrm72aaTkt7B2YNru9H7iBLVj\r\nozYy/anEIvpp4d1Sw3W/iJA0vxFTM42WyroD7mymphlZW0k4svI6rl29asl7\r\nnN9DToFBsmLGLppDJJe6oJ0GuwIx9Vez92i2K0Tjmi30nooE2cO/MJEkgxNk\r\naeTzmCsS8SF26r7hAYs/A5SdnNb8DeBAwrQHTkYtTGwgFYXycqFWDZqBoxx2\r\ndthSeSfNvVMBew+rLkArgTqi/jw7W/l5ZaL0Gz/yl72sPMhqJAmnEr/Qccm3\r\nV8Wsakm7Iw2o0gibwlbA6VGFSMvWTFG8K81xn0nlIboOdwem9Xz55/VNwT1L\r\nldc3O5L9IPMDy5SMn7BcdukbG7ob3Wnxo3/H/fm7FaucyOKecHGGJtbcaSYk\r\n+o3C4wnt5Neej1r6d+PuwcQkDtgF/ahsOLTki0jSXEpDXP0VmtxnjPCEqclz\r\nM0MvQD2DFha7c/3oW4axKw1MpXkEnbg+zYFxGDfsuyjzZaZXu1vogJAaB1qV\r\nzqa1Uf360C7q2WRczNQzoM6Z1I9y+GEwoZmj2NjbTN2AFxk9vwVunaZmMady\r\ncSWi+EFxjw3EvKM9TGaqPtJRUrmkFwVT+bM=\r\n=YpyD\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.2.1-next.2_1674819427480_0.22731979289463666"},"_hasShrinkwrap":false},"0.2.1-next.3":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.2.1-next.3","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.2.1-next.3+b71dfcb","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"b71dfcb7520b70d5e81e34a8d8a43e1383388150","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"LegalPerson\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:04:58.179Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:04:58Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..PD6xomtqqHGnxFzCArJGesk5Qj4oOEE6nvQ_tPk7FuGRftECZvoh3CxXGPExNknienTINWLat6m83pqY_1GpC_pnsySrqEZaWVreXHQm8O2Gbp7l7duObAZafwxv05eCDRbg_Y-LoGi8ixyfPQGaFbuwIEDol_3xDbbIkV76YFlenygvf1mT9YL62qnhHgC8SOKyoUzlA\nslO3L-RhXDIi-BAas2oSkrYfOweG5FtiMqn91XZnXfpKxm3bkdieSuUK9-PQzrwQpU9HySSUe9yePgLK_q2EjlWLwY-QHTMGWzqcCiSpW3DgWgG6JgIiHdWxDqTv54Ot6ap0BJ4QY9MDA\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offer self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so sd export-example --show\n\noutput:\n┌──────────────────┬────────────────────────────────────────┬─────────────────────────────────┐\n│             type │                                sd-file │                             did │\n├──────────────────┼────────────────────────────────────────┼─────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴─────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"ServiceOffering\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.2.1-next.3","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-hA2YS6HaVSGPVg1rOheg+PjMRCho/EWXX/rHBLk+TAfKrFHQlhZqmM3gVDyf/mDfzuSKg5IHKa5m+v2tUEys2w==","shasum":"2a947707444b820f416b18fd0207078cf8ca55ca","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.2.1-next.3.tgz","fileCount":47,"unpackedSize":320461,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBwrCRyG9q+50aX9tkUj03WRZRyfJS2XBfTM8A/EIqN4AiEAh0jQbq0BncMei7eIGQ9JEhb1r7kk6UqL0J0tuf41uZw="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj07uWACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpbqw//WT27NF+Z0IWmZLEx6UtzYPoMjBRK1f81jzAi94fKs6/yXD6E\r\nux5PggaeBc3AUwusDB5cYNgP/J9JnFcm4Xrq0tBpunqdzhkzl7n11rW+r7yP\r\ndwqlpmB0AB+/Gp+k+4T10rNS0kRjZqRD++d9o2FWspKCBdqaQSD/48PLp7p6\r\nGDd+bZD9sX2JJDjVl0TXh2i116JTV+b2mTduYbCFE7u7rshGM6xvMUNB2GpM\r\nK8Ftgb/N3KvaCDVN0dMM86oF8dNmuvjxasUwDrSbzPcd+JaXkHw/uoNFF0Y8\r\nKL4piZ06OMnJIPStbaT5jIaRUesa9aNNHnxLGviIAyN2D/GtaxHhPbHbLjJ2\r\nE4fB9KHCmgP1ovUDFUjk1vzs3nsWRSgF+Ne+vHhxqbln7ivymbVl1Upez45h\r\nXfg+Gs/ZdLFCpRcwUIUZrgKRR9ExIN6LZqq9kSwt7E7WyMwnfmGqEL6XmnCV\r\n1HAEUoN4tr5WhqS8JEZBv2hjrvvToX2hnEYZSxBIDFyD7p4aJa2Fxk0UTfgp\r\nFQ0XHvQibeg9D6U9Eqv8CQvg3yV3f2PpcVIqCOlmdoVCy3FHKIu6FRXlNPt3\r\nYbElxQX5ZOPvPbxk1nUdq2fIUqkA+kozYVkXKzrzU5poapjKqB8kaqzLIwZK\r\nSev4GktfOnRAxrFrWqRScyKOJIpXH0Wx2fg=\r\n=i6yd\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.2.1-next.3_1674820501994_0.1245587025658419"},"_hasShrinkwrap":false},"0.2.1-unstable.4":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.2.1-unstable.4","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.2.1-unstable.4+5dd70a6","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"5dd70a67477c9c2c77cd3f344f00d705d20cff60","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"LegalPerson\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:04:58.179Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:04:58Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..PD6xomtqqHGnxFzCArJGesk5Qj4oOEE6nvQ_tPk7FuGRftECZvoh3CxXGPExNknienTINWLat6m83pqY_1GpC_pnsySrqEZaWVreXHQm8O2Gbp7l7duObAZafwxv05eCDRbg_Y-LoGi8ixyfPQGaFbuwIEDol_3xDbbIkV76YFlenygvf1mT9YL62qnhHgC8SOKyoUzlA\nslO3L-RhXDIi-BAas2oSkrYfOweG5FtiMqn91XZnXfpKxm3bkdieSuUK9-PQzrwQpU9HySSUe9yePgLK_q2EjlWLwY-QHTMGWzqcCiSpW3DgWgG6JgIiHdWxDqTv54Ot6ap0BJ4QY9MDA\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offer self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so sd export-example --show\n\noutput:\n┌──────────────────┬────────────────────────────────────────┬─────────────────────────────────┐\n│             type │                                sd-file │                             did │\n├──────────────────┼────────────────────────────────────────┼─────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴─────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"ServiceOffering\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.2.1-unstable.4","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-20IQmicW9tilU5jIRIfWV8DuZYWwNNXuog2aFOllCAwbyq8Q5J7xfzk+7P+KW69b5FKdrPa2l7c4W1U1OzrBBg==","shasum":"aa4e74245e180526d8dc76b0d6e4959c6502a2dd","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.2.1-unstable.4.tgz","fileCount":47,"unpackedSize":320469,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIBm05MWAnVHXDmTCLKT7dJQUPQy0YQZnBqXnNKFrGzO5AiAJyjHRTX0xGGNEh7o2POuNSLOJIbxyQk6P8ZsSnYX1ZA=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj19D1ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoSSA//f+d4SX+2JTSVobl0d5dfsJ/A8Kay0xCCvxoO0CCpFDN6rn90\r\nIM3VnylXiAqRlbnp90SiflNgtByKgAYwRQzwYqy4DyfxXSu1u2bAT+IbtCVK\r\nM/ua2Prgpwft7eQ7GR47CpWfemqi3QSq36RSZTtJ11soHqxCJ+l41FgNpipc\r\nDldxbXGTERZLrAPsvmQ7h+ZB0cVgWwL5iP2E7E+syaxhkgNSTae+4BVb4+4X\r\n13XDzvPXkmTPQO4JugeItaMaJizr58Ugj182vW2zPAGmVPqrBPH7Ivs3NbZH\r\njF69751ie1gLsdzonn0hQUNpuw26l4S0FWN09Q4VYbNWjIPf2no2+oYtc/sU\r\nIsusKYucEwRqXWh9E395B5TWhgQJveWhVt6b8u6YlW/lQeMSgyZGqBhFPvJa\r\nFP0f5jthLIgpIvKuHMBHuE+1hFSDzzu9y10Qq6xWyZpaiNFYOhw6bWHBBxUG\r\nZ6EKQftIJJDWOGy5I1pR9S/upWy6VgYDbbnT8QrXrjiZuHCB2bpNdojrbxGM\r\na2hKqpskgj0q3gHaO26KSFFr1nZY+IDtPtBJguMMS8gu4cotWjWV5B+6AX75\r\nkHtbNF4npN3v5wv4BHcv9k7r1SoxNWFeiTDfEHFoE9DD7UEa0BfuIh6ZJVXK\r\nDw8S80NFXcpGpqgAiud+8UpTXfxbN4whNSA=\r\n=OrJk\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.2.1-unstable.4_1675088117226_0.4852143966899587"},"_hasShrinkwrap":false},"0.2.1-unstable.5":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.2.1-unstable.5","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.2.1-unstable.5+5223ecf","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"5223ecf760c17fa077e4dcc2ea48a99734731500","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -sif ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"LegalPerson\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:04:58.179Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:04:58Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..PD6xomtqqHGnxFzCArJGesk5Qj4oOEE6nvQ_tPk7FuGRftECZvoh3CxXGPExNknienTINWLat6m83pqY_1GpC_pnsySrqEZaWVreXHQm8O2Gbp7l7duObAZafwxv05eCDRbg_Y-LoGi8ixyfPQGaFbuwIEDol_3xDbbIkV76YFlenygvf1mT9YL62qnhHgC8SOKyoUzlA\nslO3L-RhXDIi-BAas2oSkrYfOweG5FtiMqn91XZnXfpKxm3bkdieSuUK9-PQzrwQpU9HySSUe9yePgLK_q2EjlWLwY-QHTMGWzqcCiSpW3DgWgG6JgIiHdWxDqTv54Ot6ap0BJ4QY9MDA\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offer self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so sd export-example --show\n\noutput:\n┌──────────────────┬────────────────────────────────────────┬─────────────────────────────────┐\n│             type │                                sd-file │                             did │\n├──────────────────┼────────────────────────────────────────┼─────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴─────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"ServiceOffering\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.2.1-unstable.5","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-TheT5b+4v0CzJeQk9wsX+SHUsyxtq2YcNdt+Nw9Zm/y0Pg4S8IkuHdPDedPEfxeiZGnR09Vw3zS4MKl+kzo1JQ==","shasum":"b936f9a29b4861ca829aceb22e1c6fa7ebbb60ee","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.2.1-unstable.5.tgz","fileCount":47,"unpackedSize":320470,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCwgAk+mvHn48Vgr9ASPfnVb9xBsFu7/gTucOooeW8jYgIgO7MJI6IlMaffaNhAm4ga9JNnlUZ22YFhiMSTQMdn1eY="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj1+XEACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoUMw//T4f+0SViCEs52m2dBVJ36BA9vle6d71898d++Gvzes5zRmd0\r\n6WzSKS8lS7L7WS4uEtVkMjYHSKoHId5uk5m/umHqbT/gGKIbaI2hTgN5AiTc\r\nQB/theOwvHdjXiAe8m2522+UhJz0i6Dj8Y6i8xDANLxMR6bv6JEStFD8GbCe\r\njxlZEe5h6qv0M92hWuqz95McZdgpoQ7s109gibWNlveDYV9MQpFZItRLChtu\r\ne7c43j6tKnWrFg2DxefUE2SWUE8zqJhKB4b8HGbJFmfjvSWpY10hnaA2v+oT\r\n+VoJ2vjtEK8h54DM1CSGPo2NhlnSkjtCxjASnt8SwUzICdcjk2VXuSY97bCh\r\nx5TRESnDlGt5QdQz40PgQCebUlgWxuo3CbqOAR6TDY/bSdazDyYOldV59voH\r\n9M5sPQoa/ulxMLf+8SFhjefx4yLZBDpsLnDqthOhm2qVbpGhzWjjQ81u64aK\r\nEZxe994OwI9M5e4Oth3JSqY1GvNbSgM9pVUC/RuDBRITkt28rBPAARrYXKW+\r\nLvYMTnHvjE3t4pib093bVrUEUnfOqR1L9iNzIP5vEsiek+16AJBVcbPg99Wr\r\ny0K3FV5INahxzN6AZ/yw1+w83JNDyXK3toop+VWEzzcomvE7Clmk3MM0gFvV\r\nXl8TEBK7Gt6V7Fdn2CN2BfcKPGaPqbCEoqk=\r\n=Yp4Y\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.2.1-unstable.5_1675093443745_0.02341461537579015"},"_hasShrinkwrap":false},"0.2.1-unstable.6":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.2.1-unstable.6","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.2.1-unstable.6+eab419a","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"eab419ab0e2099ed0c084ed9b3775f8a0bc28354","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -sif ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"LegalPerson\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:04:58.179Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:04:58Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..PD6xomtqqHGnxFzCArJGesk5Qj4oOEE6nvQ_tPk7FuGRftECZvoh3CxXGPExNknienTINWLat6m83pqY_1GpC_pnsySrqEZaWVreXHQm8O2Gbp7l7duObAZafwxv05eCDRbg_Y-LoGi8ixyfPQGaFbuwIEDol_3xDbbIkV76YFlenygvf1mT9YL62qnhHgC8SOKyoUzlA\nslO3L-RhXDIi-BAas2oSkrYfOweG5FtiMqn91XZnXfpKxm3bkdieSuUK9-PQzrwQpU9HySSUe9yePgLK_q2EjlWLwY-QHTMGWzqcCiSpW3DgWgG6JgIiHdWxDqTv54Ot6ap0BJ4QY9MDA\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offer self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so sd export-example --show\n\noutput:\n┌──────────────────┬────────────────────────────────────────┬─────────────────────────────────┐\n│             type │                                sd-file │                             did │\n├──────────────────┼────────────────────────────────────────┼─────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴─────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"ServiceOffering\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.2.1-unstable.6","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-tQUQbGspZ6yTokNmV7IkjlJTJc0TQdyYIbaMXBwuTMeeDRbutN6XPOpkChtzBVqnDDtyXm/FG9T+yDse5zKxaA==","shasum":"2c91d235e024c4ff9f11e62b6851a5ffe62d8848","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.2.1-unstable.6.tgz","fileCount":47,"unpackedSize":325506,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCXlpwc2TeUs54LzjUIliemD4OaMRHtXPOjRcQdIYqQrwIhAIniFGfWUL84w9Ecp1qjWNKyyFqA77IrouKYQyfjUZ2z"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj2oGoACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpb5w//SgeVAWI6kcLLel+3U+bK+3H03tfVhUt2Txkli5JMKvK9CzKh\r\nYktzvOPU1jRs/uRK0bm8FhQwdEKehLzKYbLpM1uERm5XKtZML0BQk9tlQ/Mu\r\nAv4+B8VM3/565MEcq+tuaUi4E4M45S83UOA646WPsEHKR7lwXfWhflE1EJY6\r\nFRflZu9KCS/SjzGTM8dbMlGN+ysfuRcJi1JfaN9h7bBCrG4XpS9Urur4Ej58\r\nYNQnpE0KWoYDj4IN6kd5/Bt7RISoR3gGDz7zpw6E5Z5F//xpc1zpSnhjx6E/\r\nZ+NjNYw26msA/vV4zERC0/WEAmUQR0UIqd3SFrWLaf6qtYXIvk02CHPH1Igr\r\nGUTtB2UqxhTkNlt/OMHondxACRCISY3iq4NdazR2N/gcmTD+4T8SU1v///Bj\r\nf+3rUrE+Bz6xZY3gJ6tPcobzzq1rQTZudhRnHVcxwMYi2jpVpmCpLMQLfk4K\r\nxaJAiXuR3WSW/ZmKj1kYgNMd64bkhKIRJc+uvpbyNktFE+NvHMzDnhBBaUbM\r\nL0bGkxWPP16XOxN2dAwc0U8XUna4WbnACmLN5awvayJyY93YH5ZgFKC7CjVS\r\nHQxTQj6Wpd17le4Ayzs7pgh6fq3wQb8wkT75BTsd0PxMLk8cjEMoH1TIPCk6\r\niMS5f5EXeTAFUozpMmGYy9mBuWQoxg3S0Wo=\r\n=pOOT\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.2.1-unstable.6_1675264424643_0.4400502819304648"},"_hasShrinkwrap":false},"0.2.1-unstable.7":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.2.1-unstable.7","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.2.1-unstable.7+34ce485","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"34ce4852df92002edfd5715d2c2f49651252f219","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"LegalPerson\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:04:58.179Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:04:58Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..PD6xomtqqHGnxFzCArJGesk5Qj4oOEE6nvQ_tPk7FuGRftECZvoh3CxXGPExNknienTINWLat6m83pqY_1GpC_pnsySrqEZaWVreXHQm8O2Gbp7l7duObAZafwxv05eCDRbg_Y-LoGi8ixyfPQGaFbuwIEDol_3xDbbIkV76YFlenygvf1mT9YL62qnhHgC8SOKyoUzlA\nslO3L-RhXDIi-BAas2oSkrYfOweG5FtiMqn91XZnXfpKxm3bkdieSuUK9-PQzrwQpU9HySSUe9yePgLK_q2EjlWLwY-QHTMGWzqcCiSpW3DgWgG6JgIiHdWxDqTv54Ot6ap0BJ4QY9MDA\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offer self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so sd export-example --show\n\noutput:\n┌──────────────────┬────────────────────────────────────────┬─────────────────────────────────┐\n│             type │                                sd-file │                             did │\n├──────────────────┼────────────────────────────────────────┼─────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴─────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"ServiceOffering\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.2.1-unstable.7","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-z422Wxm0JwkiAoGGCJHQHOsRbwmdDteTAQGfDPBeF45xAzCWMLxV7XuJPro9dWruiABG1jL06SHyXXFmkxkZqQ==","shasum":"0c371d9ba22559b11cdbce0d192dfa0b1abb5618","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.2.1-unstable.7.tgz","fileCount":47,"unpackedSize":325505,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDjMY8UA9D0fFy6IQtyi+T9xqdUCTMbQ/B6DhCAmfeVKAIgDrEhfIlHTk+Hcsg6MujU6EOizsslAldRgge7VKOmCdY="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj24D9ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpN/hAAnRWtD9Z7P+mUXFY+mAeDgLRhijGIz+SHixx0POZ4BEsxlmKr\r\nyaGmIr5kV5rksRztTPxUmqKx+crfghT/nJ+t80IbsWWrpo/Ou9mfHkFFR+AH\r\nuDTHOLaEMIpwfv1s3SveWow1whZ/MmWd56ekzmhdtNjQWlI/Fgzunc/aUjAq\r\ndOuFtSKV2siZJ9ioE71i3vWbTXpLF5/hFC8qDC9DvnLqb88z3eGQMHjTANR/\r\nm/Hjx4tiszR7S7gMRudLiQNvVXAqhREJoMTAosy5m8KcGUuk1lbnmcF+U8Hz\r\nIWfffYmU3QJqht/Cj2c7QUMmfqaMlj2+YIfscRBraZ+jgJfvUALnaHRMD5rQ\r\nI4c54fw8NfGnYftfnpjVHu9YLnw8s501e4vNQcu3kBG+UfCSIQIBxVrhzf0K\r\nMJQgFNCYm4fbXQI3uMdV8+iu3OvpfMDqDe5/er3x8rsQ/ZuNcz0EwqQVK3kF\r\n7VeqwBLI6nSEYrQFP4787Sa9xxLB+bKV6UA6IB/PEyCwpghdOQaD869GlWmy\r\nlVXB7pzGvzkmKNStgoSA/LjksI7nfj/4iV8Jq6z8wrZpa8HawWdajxqcS0nq\r\nZHdY8do0oz9tnV1ZtUGaPOhlUAyLgeVD76qob8eBaOiiFmRWvnu4EbIlloC8\r\n8ikd9hHX1629UiHvkuRu2tzJdsKFGNA2LcA=\r\n=lMUr\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.2.1-unstable.7_1675329789124_0.9810745521051876"},"_hasShrinkwrap":false},"0.2.1-next.12":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.2.1-next.12","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.2.1-next.12+4304bbf","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"4304bbfa228ad6842c1018bd7786dca50a8b5e41","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -sif ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"LegalPerson\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:04:58.179Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:04:58Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..PD6xomtqqHGnxFzCArJGesk5Qj4oOEE6nvQ_tPk7FuGRftECZvoh3CxXGPExNknienTINWLat6m83pqY_1GpC_pnsySrqEZaWVreXHQm8O2Gbp7l7duObAZafwxv05eCDRbg_Y-LoGi8ixyfPQGaFbuwIEDol_3xDbbIkV76YFlenygvf1mT9YL62qnhHgC8SOKyoUzlA\nslO3L-RhXDIi-BAas2oSkrYfOweG5FtiMqn91XZnXfpKxm3bkdieSuUK9-PQzrwQpU9HySSUe9yePgLK_q2EjlWLwY-QHTMGWzqcCiSpW3DgWgG6JgIiHdWxDqTv54Ot6ap0BJ4QY9MDA\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offer self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so sd export-example --show\n\noutput:\n┌──────────────────┬────────────────────────────────────────┬─────────────────────────────────┐\n│             type │                                sd-file │                             did │\n├──────────────────┼────────────────────────────────────────┼─────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴─────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"ServiceOffering\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.2.1-next.12","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-a6Qxu0qMaxwSYRDVQ26oU2Fw7pQR51b+yc0J139L6fTL14Sf1LxhBHI+Wh5qz5CYZ2UOuiUVtbTHibDfSs97pQ==","shasum":"1923bfbc8081d0fc4a1b700d00f3fb45228da4b7","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.2.1-next.12.tgz","fileCount":47,"unpackedSize":320547,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDIAYcimiDEKu69O016YA1KSlr7TP5Q+lcc8Xfal7aByAIhALeExXt1D3e0mIRPtt/g3RXu3VyTMuh6XRV61ESOTAUp"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj3hGYACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrGYhAAknZItwhA8a9TFPnuGhTSdGgrzOmW0zLvxuZ/W6DA2QGYggm9\r\nfV16zDam06QtK746ptASJs+tIS/jUbN80jQ4EkMlN0K1VzHxU0Id1+w7S5Jb\r\n6QGAeuenq9i3FtPuBo+HR6HHU3f8HMQgDbR/26wmwzQ7x0cMlIUGLYYFAM3m\r\nXkUQ/BkEZzfyv5KiHQWHILrCJIwq6TE70VEXX5TZSE43GlHuyz7fUuf9kp06\r\n07Ayv97ezT3rZK3GKGK4E88Y7ErgDg5RJWT4Mu6+WmLtWISsWxVZnwWinHlS\r\nUUef+0KE3NvdgmWucJf4d+kKr0GXuh4eCjfKp3auaAnYNVLyKvIsUl0pia+a\r\ns1SrEMjUWd9CInUIQGvl/AFAfHEQ1TveYB4jmkY5KcIAhhTRGhKp7DSbcgJc\r\n3zBPfqh/tdwhTj0SKYDVAj9H0Y9wnAq7/eMSR82QOx9XcMVxLgGiQ1jtMzYB\r\nHCAslBH13/UQwo+lGWcGJ55AGSjo3ugNmOdG99npYhi+RluoPTmvofkL8m2E\r\nNKk7ont+wnM301rfjK5XympJFeHQap/KATiPEO6loxLbTAy3rsmzdJI429dy\r\nsnmnEwO+TtGrribikBlEk5XOiSn/SGeWXyNxEbojPFr0OOQvYsv29+EL+dC5\r\nyT/6TgLvcjVk5iPY1HY8ZnZzHpFiCEyUhz8=\r\n=DdWd\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.2.1-next.12_1675497880695_0.6569945596439639"},"_hasShrinkwrap":false},"0.2.1-unstable.21":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.2.1-unstable.21","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.2.1-unstable.21+eee60cc","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"eee60cce88e3dddaa2071299024fa4d5ec16c0b6","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"LegalPerson\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:04:58.179Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:04:58Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..PD6xomtqqHGnxFzCArJGesk5Qj4oOEE6nvQ_tPk7FuGRftECZvoh3CxXGPExNknienTINWLat6m83pqY_1GpC_pnsySrqEZaWVreXHQm8O2Gbp7l7duObAZafwxv05eCDRbg_Y-LoGi8ixyfPQGaFbuwIEDol_3xDbbIkV76YFlenygvf1mT9YL62qnhHgC8SOKyoUzlA\nslO3L-RhXDIi-BAas2oSkrYfOweG5FtiMqn91XZnXfpKxm3bkdieSuUK9-PQzrwQpU9HySSUe9yePgLK_q2EjlWLwY-QHTMGWzqcCiSpW3DgWgG6JgIiHdWxDqTv54Ot6ap0BJ4QY9MDA\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offer self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so sd export-example --show\n\noutput:\n┌──────────────────┬────────────────────────────────────────┬─────────────────────────────────┐\n│             type │                                sd-file │                             did │\n├──────────────────┼────────────────────────────────────────┼─────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴─────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"ServiceOffering\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.2.1-unstable.21","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-cWzhZoP2J8ozLn/knw3CFLPC9wG5WpAYCQVJAgdRGqi39h9cpMVixUDe3rG+CjCdgfFGPpOJUtVYQ6xJicn6zg==","shasum":"13c699a8dfa41700dd2969493cc042b42462f76d","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.2.1-unstable.21.tgz","fileCount":47,"unpackedSize":325712,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCAWMXGGQo5TX5P/o6E0o5vrMx3KDOPGlVkMPpIxTkVJwIgVQyc3TFKsiKsAc0SXHuGM56AxptaqfJWK6ds/rpniCY="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj4QXnACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmoyeg/+O7g16WB3+2Qcd25JiNd6tQ/Or03OuKb6s4/pVwt8UQmhU/5l\r\n8c7MvrSeXwMWBM5DP4NmuBCc0Zc/f9nUatC0uDY0CilwgGUQILSjYot2iqft\r\nciyJmDToysx2pptyjoZTRJzj5xKpNE37YABAJo2micGG0h4Hab+Vck1KRXsN\r\nurlyzG7J+zKQQEdfzQx///KCEwEc3qQN5PinFaRlwvvgnVVHhQbei8ovjx6L\r\nxQvi5hyFhr5bVBfCA56GYuBFClHtzbtnmXhWx6HWPupDxku12gdNeKYi6QRs\r\nB0+iZ5+OgAVCQjAcJat5vSI0ZrbIUPz97Pgmq1dKe20VxEkhQzeWrQ6aSqaV\r\nPVqATOgTxbu8MvbmNeoQG47q1QfOenO8FIvH9seDp+AOoAqajLQZemfpgOAI\r\njjalwhIOyVUGHUWNHu7xfLdEdbe/R5b2fTG8DO3X7e9QcQq4dvVpXfGa3ywc\r\nxqdbIfATHDRCXXf4B6M9z3Usd0gCdRs37dtwpdz+r/6lLvpOsJgQiGFcQKYN\r\n9zJRLLlwqyQzKesWXQXtvW1wWTuMjSvwf+zfg/LzymDqgKDDmnONwThBGuzb\r\nLDVZC4fgxzbNePozsBEk1FpvbrrbMMBSmBki15I7PDFZtwjmSk4UilZFv3Yz\r\neT/86MwsojrrKeAUJ7MofvZD/aCBV8EFo0I=\r\n=VsAM\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.2.1-unstable.21_1675691495216_0.8348083763905616"},"_hasShrinkwrap":false},"0.2.1-unstable.22":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.2.1-unstable.22","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.2.1-unstable.22+551209e","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"551209e4033bcb7dcdbd2c2bca6a355a318a8e52","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"LegalPerson\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:04:58.179Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:04:58Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..PD6xomtqqHGnxFzCArJGesk5Qj4oOEE6nvQ_tPk7FuGRftECZvoh3CxXGPExNknienTINWLat6m83pqY_1GpC_pnsySrqEZaWVreXHQm8O2Gbp7l7duObAZafwxv05eCDRbg_Y-LoGi8ixyfPQGaFbuwIEDol_3xDbbIkV76YFlenygvf1mT9YL62qnhHgC8SOKyoUzlA\nslO3L-RhXDIi-BAas2oSkrYfOweG5FtiMqn91XZnXfpKxm3bkdieSuUK9-PQzrwQpU9HySSUe9yePgLK_q2EjlWLwY-QHTMGWzqcCiSpW3DgWgG6JgIiHdWxDqTv54Ot6ap0BJ4QY9MDA\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offer self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so sd export-example --show\n\noutput:\n┌──────────────────┬────────────────────────────────────────┬─────────────────────────────────┐\n│             type │                                sd-file │                             did │\n├──────────────────┼────────────────────────────────────────┼─────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴─────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"ServiceOffering\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.2.1-unstable.22","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-7chAvDY8vzg3BiB7bF+6CEx6Y708wacc1SqAopVgiAJIo5V9Km6ZWYtRpT18XULPrXix3/HRD8tCoEDIBzjOBg==","shasum":"170f25b363ba48f70b2236e30ad0336436a64fbb","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.2.1-unstable.22.tgz","fileCount":47,"unpackedSize":327823,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDIDbYRcTviQaZxRdIYuB9WA5v1/nJJfuLMIhIJckQOsAIgPqApWaKQVusJgQRzotULPKwB7GkBr6BKezBpDTwYSS0="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj41kCACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq+Cw//f2ZWM71JvPkjtAypgvjs1m6jwEPC8jJzapDh7VIE5pSNGhvJ\r\nqaMWLnHH3CN7Ql3PMHpCovdk3Fjr1gBMajWJcwggNjRyz7MdrxtJr9KAmeoa\r\nE2vQRD+SDtdT3AmpWKbPv7PwBEG8LTKUXe7i4qVcgtZp42SaRNSGaNc4/poO\r\nb6KVaR6Y31NMVew8zSbFheNFJCsH71WjJF5xb3BHmshCScht8SiVqKacZkxA\r\nlDi9DuykbmgEex5rimk8SDOTiZ7eyyMIWitjwddbN0gznCTWotn+zuCXV/6X\r\nBRadqoyvSWDzAgXGFCWFvFOKZutbcTsp4WxbDxxOa5GkitXHtXQS/RIs1B0m\r\ndGn3wLdyXA0flAxUURjtkg51X44hUt+q2K7KeZdxTD6G2vvL3EHJ0xjwYUTd\r\nYINA4hP9BKWNSYx1xTBOzJx5qb+iSyKaWuM+/KyUjAMdeqog091yjeEYiwK3\r\nx0yUL9YmdDelcv/d+Aqb/b6Fm/Og9dNFCroWgg0jmHNSRpzLQMXNaHYFnuG9\r\nzBx3QZ4OIRxcd06iQLem3S2LEpYm95aI7Kcd+uxyl87XzqIt8CX3D5sfNNx2\r\nmdldxt1RAGK2/oG3cTQKVy6CyM1DdZcFpGOrKInVxU0Ke/slTVSUBC7MnXPp\r\nEH9nkJYq3149D+rSiFbeyENx4YsF8HWkbVo=\r\n=59h5\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.2.1-unstable.22_1675843842623_0.24663177079879062"},"_hasShrinkwrap":false},"0.2.1-next.23":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.2.1-next.23","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.2.1-next.23+0233c52","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"0233c52e05c1f704837ba4124b365702d9c93891","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"LegalPerson\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:04:58.179Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:04:58Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..PD6xomtqqHGnxFzCArJGesk5Qj4oOEE6nvQ_tPk7FuGRftECZvoh3CxXGPExNknienTINWLat6m83pqY_1GpC_pnsySrqEZaWVreXHQm8O2Gbp7l7duObAZafwxv05eCDRbg_Y-LoGi8ixyfPQGaFbuwIEDol_3xDbbIkV76YFlenygvf1mT9YL62qnhHgC8SOKyoUzlA\nslO3L-RhXDIi-BAas2oSkrYfOweG5FtiMqn91XZnXfpKxm3bkdieSuUK9-PQzrwQpU9HySSUe9yePgLK_q2EjlWLwY-QHTMGWzqcCiSpW3DgWgG6JgIiHdWxDqTv54Ot6ap0BJ4QY9MDA\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offer self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so sd export-example --show\n\noutput:\n┌──────────────────┬────────────────────────────────────────┬─────────────────────────────────┐\n│             type │                                sd-file │                             did │\n├──────────────────┼────────────────────────────────────────┼─────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴─────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"ServiceOffering\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.2.1-next.23","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-MVFLZFKv7xSuCvDLTgUGHmOGaCx9mFUuuA47Yty68CuN6eZtEqui2ZQ5Qqy6SwpQVw4RZ+GX9cRv7DAEFYm8uw==","shasum":"e849cdf30a4c361f66f30aeab4093b519fda3041","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.2.1-next.23.tgz","fileCount":47,"unpackedSize":327815,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDdWQ52SCmd3lQ897dGXMJT1nwBtz1gehqAnhlecyoWLAiEAt7+YaaiTEWqqlC6s4EW1LIzvEuNUIWyu5tt4+Ndkqrs="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj43EtACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrDHA/+IFjQ4+3m8An9FRmg77wIvu9mS6QgjC2gVDK8yXrJoBN+x6rl\r\npc0ltsDJwqQ3fGmseBuv7emb7H1RD+KTW1NkyDX/G2/TXN/iAa/oh2EbBgqp\r\noUWlEO0NXJoE64/X5on2ku/rh/Nfb5qfOx9n65By2d+FiQcBAKpTLsMyZP4+\r\njImtZSB9h7ONHdsptI5mbrcTuY/ql+mZ1BK7BULMzIck2MQ/Sk9obCbIlFEo\r\nBaPkUyaFgInO/+bvF7ECOWJ/7ZPBT3mdvnr7HSjwgxnU0dV9TmR9c51tlQfI\r\n8tDw+EAAZQDkLEYiNqegqh7ttjXxrN1e2u248DbXlU4fCBwV2ql4GBdS+7nT\r\nUM8rSpUeeoyymMMES7Pif//WxO8dvXQpS/dCdMg9VWVDZ1WXio7D6PHBgXVd\r\nqHUMiyiOdaeFYhf8dwQgKVpcwdPa9aIAnPFoGiZR62ANyjPe07dykpsQEL3r\r\ndYxwniSMJdtbfXOTHkmW9Aotzc2n86o648muZHSnXOiP9EaHiCt8xUtVpKKM\r\njwd5M52mzLMJqShYD3Uz/Qm+fPTtp9muGydqEhoVvn1Kfw2x3THociXMFYbY\r\nK8R+CndVqHYX5/UiDuNTGrKaPrMIqYmzi/57KtQXkUmjj9NlRxU35i1WAHZX\r\n90/LQOBGsm6WX8VPptPonhsxgaaJWhgrFqI=\r\n=nIeb\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.2.1-next.23_1675850029612_0.6883905801621644"},"_hasShrinkwrap":false},"0.2.1-next.24":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.2.1-next.24","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.2.1-next.24+d9ff4de","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"d9ff4deb46f30f05df00dbec4f576ea4477c74cb","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example participant self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"LegalPerson\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"816826d6-8e1f-4cc6-89a6-a77ae4b63771\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-participant:name\": \"Example Company\",\n    \"gx-participant:legalName\": \"Example Company ltd.\",\n    \"gx-participant:website\": \"'https://nk-gx-agent.eu.ngrok.io'\",\n    \"gx-participant:registrationNumber\": [\n      {\n        \"gx-participant:registrationNumberType\": \"local\",\n        \"gx-participant:registrationNumberNumber\": \"93056589\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"vat\",\n        \"gx-participant:registrationNumberNumber\": \"NL001234567B01\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"leiCode\",\n        \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n      },\n      {\n        \"gx-participant:registrationNumberType\": \"EUID\",\n        \"gx-participant:registrationNumberNumber\": \"FR5910.424761419\"\n      }\n    ],\n    \"gx-participant:headquarterAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:legalAddress\": {\n      \"gx-participant:addressCountryCode\": \"NL\",\n      \"gx-participant:addressCode\": \"NL-NLD\",\n      \"gx-participant:streetAddress\": \"2 rue Kellermann\",\n      \"gx-participant:postalCode\": \"59100\",\n      \"gx-participant:locality\": \"Roubaix\"\n    },\n    \"gx-participant:termsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"LegalPerson\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:04:58.179Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:04:58Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..PD6xomtqqHGnxFzCArJGesk5Qj4oOEE6nvQ_tPk7FuGRftECZvoh3CxXGPExNknienTINWLat6m83pqY_1GpC_pnsySrqEZaWVreXHQm8O2Gbp7l7duObAZafwxv05eCDRbg_Y-LoGi8ixyfPQGaFbuwIEDol_3xDbbIkV76YFlenygvf1mT9YL62qnhHgC8SOKyoUzlA\nslO3L-RhXDIi-BAas2oSkrYfOweG5FtiMqn91XZnXfpKxm3bkdieSuUK9-PQzrwQpU9HySSUe9yePgLK_q2EjlWLwY-QHTMGWzqcCiSpW3DgWgG6JgIiHdWxDqTv54Ot6ap0BJ4QY9MDA\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offer self-description to disk. You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so sd export-example --show\n\noutput:\n┌──────────────────┬────────────────────────────────────────┬─────────────────────────────────┐\n│             type │                                sd-file │                             did │\n├──────────────────┼────────────────────────────────────────┼─────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴─────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"ServiceOffering\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.2.1-next.24","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-Dzv5Mg9V4u1WuvsR4z4y7KESbV9rUp1XxXEnwPnwFDw96P2ACR2Ga09zWyGvZhrE8X3quAbJhGpbfPRgoXNIug==","shasum":"9fe47234020283575704f2d944078c543f933a64","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.2.1-next.24.tgz","fileCount":47,"unpackedSize":327815,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHP7yhgYk2l8i+zjs0wDqLoLDHr+WND5KgdMlOOzhguKAiAYfuvuDh1PPgYUxYTE4vG7TYTmscGM4cW+H2rWj9fR/w=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj46teACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmot4w/9HVBms3MkwsrOEM+rA79vjjs/ftKkH1oEY23vD+wEAyGzWsVU\r\ncaep1bgYHQ1Dx/hAr26lqg+a1Lwl6eKQs2BiE9CxjyYJVfgrGKkXcA2N9sI9\r\n2v6fgqKQygLv3jWTGU/baEa18rlN7DvdjRDWZ2Cv4TBfee9wRY+8YOTHPUQ0\r\nn4P24io7zMEnm22cSMLI15B+6eqV213/E68xB7mB4Y3scPJ9dHQWgCtG+3vZ\r\nqcS6GTjYVKYx7IvxFVxOOaLHn63I2FKHCvDlXBZMIFfHTLvLbUmM1Fwbh/Fe\r\nhCYEicIjQxBuCQqs0axgZwfWnxlIqUwY9hHqeTnxS3XRwCM1JYwboHn5T6ey\r\nQNYRL6jGmNqALm8gv7L5iEKvo4pwwwWLkNVNl6cPaTvuiZQ3/ZM4ATFWFCcd\r\nS+/ri3DtsijsJhSIqAnHmZaQobnpESlyr0jnXLTdKfF/zedH6GVMsMnB9SXo\r\nhsWDEbXNPgcoDWDPHIDjdT7DHvqai5k49aZ8gG4C56jGYojpm7JXThwzMCn7\r\nn1YjDG7dopJCkixKeg5wMuWTEETAnVRHrvkh1+ZVfRdFzNDl4ePyn/bAxxKC\r\nDg4Ihu0K0p7YFEFNacf6PiTJD0z6dByI7t6HpaLlIgrmEmzHHYqsGKG9NOAs\r\n+lcv4FOoM/38kPeUu5aef6de7o+a2hQvihQ=\r\n=WFAS\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.2.1-next.24_1675864926451_0.5780292666465592"},"_hasShrinkwrap":false},"0.2.1-unstable.32":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.2.1-unstable.32","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.2.1-unstable.32+616f4ab","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"616f4abb64e3a4045696cab67a14fb6363b9d57a","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.2.1-unstable.32","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-VbUvJGA3zTZOVeyfFb1K3Mp1CHnwjsSLeU5JNu8DVVrc6NMILc99LreY/RWaHuPzk8gSZuzyXb5S0f9wCz/Fxg==","shasum":"326d06cfae9d349d38babffeb005f225d8afd4ab","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.2.1-unstable.32.tgz","fileCount":47,"unpackedSize":338580,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGbB3rl1rvXwlTlWLqOflDr3wBDt5SWS8gnSrd328DUCAiEAqJgaXOZqkz3cJ6FHNcjti3yKIGbB6OX2EKb+EJS+F7o="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj5kL4ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr8vg/8D3cpnubtjQ/vdbg6SQDLECx0csMFWHA+1Nz4VASJ80416tSV\r\nSUHnPpI0a33bxc5lhUPYp6pUeRjFbpi1hyAv2A67bsutRhDlg+80mpVRkdJS\r\n2GecIMK6oWcp5ZAau6DWiuUihYk4593Q1AQJarxfB2ckhgxg90p+Fi7XqT3Q\r\nVdA1yLfq07UpQcwGG8OD5vA1M351OmuZp/ZyenMo4+fRZMRxRJnlLHHYPQsR\r\nj4BNUXZ+bwLWvHCFzGX379hQlkM7iLqCYe1WlHzA+kowvi2loWf4uOMg4+ZL\r\nU/QpAY0p+f32Wk1D7SfrSHkbPLwkCg9Xml63YyOI5uFkkctGQkLR8/HgbkzH\r\ndvAfsuTqd+HERIcau6mmU2+uo2NPUZFIaEZVeRut9o6pOzf8fuF5hGtjba43\r\nS/coG2idQIhB1jLTvnbVJxleJJ8TLqNYdS9MNkHPyYq3nLHaBzjrgiYL8OrD\r\ngfvKOU1sD6/eBwc6KOIFLJjUz5Jz21nUq6quYOiYI1THgZ/uzTppehIzWmkc\r\n3oVfAxh2sElzGGuEP51ycBMpUFUW1cSmSisleMCnMnMRDlDhKAXBt+wiiGhP\r\ndeBsgfYwL+SqPOwLADKJZs0UuDO5UFuuClZ9aJcImdS/eMVaqckBRSGS4SaM\r\n/TJfGIbTtMwLfKBdnTR30xksgojuRm6TFMw=\r\n=gKWd\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.2.1-unstable.32_1676034808338_0.7512385218963487"},"_hasShrinkwrap":false},"0.2.1-next.32":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.2.1-next.32","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.2.1-next.32+616f4ab","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"^4.2.0","@veramo/core":"^4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^8.2.0","inquirer-autocomplete-prompt":"^2.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"8.2.5","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"gitHead":"616f4abb64e3a4045696cab67a14fb6363b9d57a","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.2.1-next.32","_nodeVersion":"16.19.0","_npmVersion":"lerna/5.6.2/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-lXVyg9OYc75lwo8rUlm9R9A09ilpXXbcPQAFsVljThh8IFmeEEDXIKTImtNuppCaht7aY6ya8Pa1GD2hF2V4KA==","shasum":"c2bfd12c03ec29dc44641479f1a6fb682f92b0b9","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.2.1-next.32.tgz","fileCount":47,"unpackedSize":338572,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICmjwupNyxGcBjc+QZCOzTf1bfrcQu7usYTFb/jXEkSyAiBzHaYTgDiVJaQC4WSgdxhxk8m2kXvzoPir7f2IpwyPfw=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj6lOVACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrGcA//XnHgu0GPy+I8viB8tZ3+6CGWMAcIZQbakr1ME6kndfXL91oZ\r\nDkrQG1GIipXpAIYNcjUes7mVaNJYHgkdwwXvRSrJB+VuVop9Qi5Sv170MZ7j\r\nRGCMn8pLskQsl8KxVpnjSyDIPPXrGcaxsqQaqAr/PVkOINwODXGKdI+aN22/\r\nbClJqtAXGWkl2bNnlKOCAlcT5O57oo4GzEuQ3Dk/gRWRPkJGYj36xOWYzj6L\r\n+faZT8iSwFt7CG8q52IEcwyH71c1D3P7RLHqqHkiffiDmcU+1kBkzLqYRzDZ\r\nJz36YMYe/BbstXmIOpbxpflroRoeNzr1sfpXYrJfasnbzk4Ebh7T6/RtHF+u\r\n9dhIzqDkm8yLFnQq8/YcIoDtaPeFEmg/1l71FwqdiOwhj7b0D48ez3iHhg4k\r\n3i78j2fG5hC7gNnn0y8yhAjSk+5I5DQPp4KdGdaVCZYaCYpqTr02cPGxDkAy\r\nfnrhvZyi/6X1BDW8ss8DAeIgcuIyoHbY2ZWxUO/GS9Jy+EGzdXZOMrW75MqE\r\n/091KQMoGHSQglaVTqISxRX/bh7nmoKnG65vb4geQIEJwzA5GdTJUkhTWJ9N\r\nekqpNIsST6JLUVa1kA9gqf+LGQCy30+Vy38dnFKqCHP/ANMr5BEP1SKNSoWC\r\nVoWKkiaCporNOnrq3bBgcs4N8MhHt7IDamM=\r\n=JcyV\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.2.1-next.32_1676301205478_0.021188119404331962"},"_hasShrinkwrap":false},"0.2.1-unstable.55":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.2.1-unstable.55","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.2.1-unstable.55+8726bf7","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"8726bf7dfeb111514e98de482e8b754f3741cf5c","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.2.1-unstable.55","_nodeVersion":"16.19.0","_npmVersion":"lerna/6.5.1/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-vKwaoYboFZOv68tQxTJOz5cSVP13CS24mFH7XBkyk4DjCQnIFQCCzTdf4rBeVU6v8xpu3JzNkvYchWT1iEF1Kg==","shasum":"b3a19c7a83ab6ab4bb59a9e7394ea2cd8c23436a","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.2.1-unstable.55.tgz","fileCount":47,"unpackedSize":365941,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEsfC323gVSa80UjMZ2kyx03oPVYwCgdWBYVZm7RUgVtAiEAg1hsKz4sp769S0pDBdsuBQ1JHQ0yxKN1Pbvn+4xcHn4="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj7AEjACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrRaA/9Gl1C1ras0PlIYi/4hPLSgZI1lJNcitEdE0g1Q7xC+ptTJgV6\r\n8moXR8HltyGLbJR1COnJFW6hBcC1CqZPL4PjWhXvEgERExKiRxwNOy4KV1qX\r\nAhawMUX7gv6kp+JFhdlqqI/OwplNzZv2oR+9bp98kq20gyExMwyLMl+vEXe7\r\nY8XZpAesKi4xX/2tGSA9UrhjTRiTf2cn4yJ9bfwnRjeWV5eue1MxLXFQXJUU\r\n5vO8kLGIPmv2uCWqCM2NAXO0YozmB87/kMtH3d0QQ0wY/OdRTzT2pmAfz6r9\r\nBf3MAHDQutKQHEsBXrKEDoE8fqhx22o2i7KcQwmPWO7iYRXfvFg14J58xiEY\r\nBhba/kKsjY7vx7e8PTd90/vYPzEu00AwSMLGt2kFPmcow38+RCYpRRNgtHbd\r\nZxUOsAVIiasQZrl2sEH4+y3RAbKNIS68QOqg4i2kHf93hqGzsb6EvReqml5v\r\nYWJgU85aBxe49DNOg7koUWTj6LM88sPqzItRNThQ8JBG5Hv2zLzdXItdMyAl\r\njPe9RtFWgQjJgy3uV09afpNGF35Q7asDB5osLjuBmtD+Io6AHwH9Kp/l0242\r\nRMGey4ZZW0ZIJLgSfu4qfiTto8Og0siy8Hizhe2aC0ptxhLegfbYxxHcLVTM\r\nX+09MCPQkriqzU1kYOsAiWCiWDLLJ+Jp4i0=\r\n=mA1Y\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.2.1-unstable.55_1676411170794_0.44778721748044936"},"_hasShrinkwrap":false},"0.2.1-next.56":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.2.1-next.56","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.2.1-next.56+c1dcea2","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"c1dcea29025f528ee4898c3679b12611c4b04867","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.2.1-next.56","_nodeVersion":"16.19.0","_npmVersion":"lerna/6.5.1/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-MJYd/kIE3xM64CnRQXUTMFtorseRHgNASEFbvru1oqkNM0VywdzLJjJf8gONqw8V6g8bEdwqoJ+I6WTeFGRCqw==","shasum":"d4a0d3345c8f3e1dcfa1fcdebd1ad88580e55355","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.2.1-next.56.tgz","fileCount":47,"unpackedSize":365933,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCkGLk98SltGbpxEw1pg0+hv5namB+LcG8kDDlFeCZ0igIgZ/Pmzz0xMbsfqb04UVY7Q6C/FaDg4jNje2Nl6yt1+3k="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj7ALaACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoBPw/+NY1M4e42y+f5zP/nVQYg6RyvgVpPBKbO75t6bU+4E9Y6gsoT\r\nmbh/s0ioRHegyNA47KmETHaB66hkeoKMtBgBtg2Atp6NbgHvsC3fATIuO0rN\r\nc9yzAakHnPRWupIRigJX1l//I0gmQNWXWeGS2+tXttmE5MkmLgn2Ss19o5hs\r\nVyYzZ6qPMWbMdLjKfyjtJgcCAuZKzlFczgP3zRSTV6xKB/43bZK07JwBHu8v\r\njC3UZwIRQCaG8ugFdU3IJ1IVWsLGSvhTm6VjpWMqgJEa04McZbUZYqwga7lE\r\nhNOmAO+X4AgaRWZNoRGgyrQugB+ouQosSIN2aXeSn5FK1K0tQ5sp4RzRERt5\r\npXXJJ8rcpSbCRbI4FXBBGNC0aO56i+Nn4NcpKEnJVhunAXuTKn02dfqTl/TE\r\n2OI9iaHGi6zx4m57EVpsfj4jMfoPXPtM82UDwoUtUA8Dd5ILMOCZYAPSwrk9\r\n3w1YX5rh4QO7b4K+85X7fIQjk9NFVdzbN8OGyQCk4kdXcrfJmZt1uY8nCCUP\r\n+Lg+7bN2Csj3JQRJWHtDTxrrNsP1iv9eyRLwMxqYYbPAb3wNvqbVhojsw7Dz\r\nK38wbZknLwdjRxF14w10DUB0wL27H3Q4ukXANlhSgtqScFCrGzL4teKVo7jh\r\nCSw4n7+mYA23RkCVPdp/Jw4Fzqzr2tx5hgw=\r\n=/qOG\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.2.1-next.56_1676411609847_0.693905965791632"},"_hasShrinkwrap":false},"0.2.1-next.58":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.2.1-next.58","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.2.1-next.58+2c99131","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"2c991317309397593486b9c6dac564bb616cefb9","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.2.1-next.58","_nodeVersion":"16.19.0","_npmVersion":"lerna/6.5.1/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-Y91xvRh9vorI0TS3mmUPWVp5oevNI6ixELiDsx9isvB5lzU028foII625HpC2pTL0mViDNyNtlHhdgjGiby1cA==","shasum":"28bc260068c7fbe6fc08398090ba733e2f3d9664","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.2.1-next.58.tgz","fileCount":47,"unpackedSize":372569,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIC/QB6XXT/UFRMCSXY3+XTHgHISF4jDTM0/TnrxANIqZAiEAgtpdAzbzyYDWWvsrMAl07UeS2RiBIm8QqeZid14gbNc="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj7CCHACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpQ5A/+JDD8tyNCv/KaeekeofHy8Itbh+yUraMvhuVbCJNo+hpzmD2q\r\nquKg566FCFyFxAaYmYew4ue9O5tdg3qDiLEWIiQT9qEmry/kxmzCtLfy5PYg\r\ns8lhaNSYZZcXJZXbvPwymVpJXJe1zBHLJLnFI1NADoBn7HGNEgfwOmMqSq8T\r\ncu5tjE9mgprSav2CQXhCwzTwrL70jEPQS04vHnbgis1RzCvcSqBkS7uZyzIO\r\nZPPDpVmsby7YuafEMCG9o3BgHqn/xyBErOwIHDMV3IqqoFZdOYGLiP4ScDJ/\r\nkZGtyuG2l5o51Prg8er4sUmt2DwCplWaVF5BPypelmlSOqtRtpHEg/NTZwiC\r\nZHWDeMA3lAbJ12EJ+LWw3VgPpIiJ23ojQHIlkLWYyvBGLh37jPzwpd9UT2yv\r\naRZ7513RYkOiDwKGZL9bl4no+ocABdd1Rkq8SuynKojxgpRyAJSCC2D5uZua\r\nLRnYcfkpANt1/RXIIS1gk9YnNRybhoVobAu0JVOBRpEn3q3WGpH3pkaxb1Jv\r\nO8hOMYgS8miYQfjbwBuAhynjdxz6xY0USMWLYy/QczKiSxENRp4e1UzkttMr\r\nbsDhCnBX+OfaiLuyeJdeut1wozhISQHgBO4R0QsMO1V9g3YckHklrexprEki\r\n0VaYW5fVBaU8DizwDBUodAE7fcsTrtft86w=\r\n=raU3\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.2.1-next.58_1676419207458_0.8786946648426608"},"_hasShrinkwrap":false},"0.2.1":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.2.1","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.2.1","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"144e955f7d6affb6920aa8ccd2a9130c868ad1a5","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.2.1","_nodeVersion":"16.19.0","_npmVersion":"lerna/6.5.1/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-ndUdlxUkDD+Z2jQ+eMgCCsrkjfkZrVxLNs0h+BqP/jEOfY8rTdbX2lmDlGgvOVrKvkCco8hnW9wLgrxA5q4odw==","shasum":"38c91165d5cd9217acb2e10d6d0d62621010046e","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.2.1.tgz","fileCount":47,"unpackedSize":372537,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICSfxe4pX/kwwFhAl/Jnu+XsRO0ePAH87iNQo/QeozqDAiAz+u6WVykIJ25EC7RJySZlTWFrLCSibVRk+4ZMMlTQMQ=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj7I1gACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr7Pw/8DSJQQ/RWCrkwugR1XoSjJd27zpY57CcRJL5zs/orcqjrLZG6\r\n6j/AYRGcRF8+n4S2hx0tBVr4lETDdx5h0H0RPC+cxcNdBkg9NxQD84oVEf5J\r\nOaGTpI7gS6mBAT3DX7UJuezUXbLYKYkA18h5hVNVaTuQb/a+PhtwuoK0/AFq\r\n5Ovcl5vI+qD7KS1uMYMWAGz2OevtYHry/zR/0oOd2RKxHbvfOcCnijadwc8s\r\nVY2GGlgBw0XHmp2sWLW0FzhGSxbx0DpE+cmpWexnD/n2AqsvJPxljIiqUsBk\r\nELJFGrjtchIq9zQdZrhtIm4seFE6XoyqpzbW7hlaTKOPE//DxyMUTgi+gzEf\r\n5lDqe9r4T5E/JJQ1c1Qh7EnPy5qaLOMHpWqokVhuEdq0ff4MhvSBeipgH4TC\r\nvChA0Qrfk3LCmJwXa6+gSHSY47eF0+k1/4dfbnj2SPV1oeMDVYn7DUR+PaoS\r\n5E4TXKC+RqQ/PEGQGCAKU6saNrcQQRFA+/lp8fgCmRQiTB19aQJiHGGNX4PF\r\nK4UhqGKHPMWtlaMB+h2ahc6MT4oCYUDOJjFx52HCTmWrWeFMd/ird2pmOrFQ\r\nhqhZLWfHPDngJOiDlXtBQn2LFB+4IO6EGqLbEsMVuV+wJTAV8QnOJTyN7zj9\r\nEm1Med733TucsEZ/I5pyeTu2doYqw7OloMo=\r\n=9WSY\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.2.1_1676447071949_0.16919274742309387"},"_hasShrinkwrap":false},"0.2.1-next.61":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.2.1-next.61","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.2.1-next.61+2f5a07b","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":[],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"2f5a07b284ce5391c824ecd1e710baf5e6d5bd4b","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.2.1-next.61","_nodeVersion":"16.19.0","_npmVersion":"lerna/6.5.1/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-FgC0rJ40NytwSQP0n++eHNx1kfKqccyj4hrTmgEPpIrA8uHzKsriIegjZ1BMy7fjOA6otS5FNEOi+9YsSPExvg==","shasum":"6ffdbdcd165ba8fd07cb92565fe27deb92d78b47","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.2.1-next.61.tgz","fileCount":47,"unpackedSize":372715,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCEp0aFce9bsvV6dn/Wwg1pyKC+QPnFZs3XdH7SJt9cpgIhAPVSRd8xTDDSSU7FbbZ8MHIiGASZwdUTVe2xA8Pk0y0M"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj7XPTACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoPWQ//S8yHyHkpD7K6iezdPAtBI0H7RzSN1tpiqP2EOxp9bUrIjH+6\r\nad0F4FbpT+mupdeKTCqN8xaOZo96r+1YWTvvINX8tsAarVFizDzfrYkNyrZM\r\n5Pb6BmwxqiijU9zCv8VnbyZ9GBb3Sz1w3gn5kE5pgAG7XoBR+g73smvxR/it\r\nA3rkfrk3rXhwRt2dmpJwNvXA4e+BpDpMe+NQ5stFWSL0e9wQ22EOLNE0YJtz\r\nRE23DeuKltTRgQLben1qMMoWqBpEmu7UcsrQg3qkzQLesLzQqwvg7AOU9KzD\r\n5pY7uaXC8ierJh6CaPovpzijMt4udRlg5i1pYxtOg/XfJkMs4LI6RQBYOXs5\r\nOuh6t5EvnpGX212nOxV/bv5P41Rm4G/AUkvjFAgGyn9ot2hLPqP8Q7yZD7wa\r\n37qc+SJk5yAtkjhWqfgeGVHt0SyUAfj9YQp3/k2j1fZF1uMREOShFUGfcO4K\r\nuPxKzL7R1F0aeJIb3L1v0khE1k8VL+1pBa9UjGLG7qR1RxL5KolUK3O6/xNm\r\nz5ZU6C6XXhEIkXdS2kUzc9JZrMHKtOlyht+qqsdLfEUYbtTwMIxUZel2X2ji\r\nHNM7DRP/iIKjd6cWm+B3CV3YaK7Z4z2mx3wmmCm7SecLq90rhEePPzvtuNfe\r\n9JZuUzKVWrLx/JbpibSfhO3QOPvT836JJkQ=\r\n=bi64\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.2.1-next.61_1676506067192_0.13517014869072153"},"_hasShrinkwrap":false},"0.2.2-next.63":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.2.2-next.63","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.2.2-next.63+440f1c5","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"440f1c5c6d47f12237b31b1449a403ad7d79c9e2","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.2.2-next.63","_nodeVersion":"16.19.0","_npmVersion":"lerna/6.5.1/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-5NVMFOVP9DuyPhoFrm8l8fcBygO91/JwbJO+a6XFWwfqKquP/LU5tvMdXzguT+euJLxpQ/m17aPxaw055TwW/A==","shasum":"67183b3faabc5e893fee3c2223ee660b565f9f50","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.2.2-next.63.tgz","fileCount":47,"unpackedSize":372766,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCJkCh4Ni65uwFqtdoQCkHaQENOndzzSqKqv1njdgu4VgIgPUcGhnj0AvC7afZy5OT1gS32KrBRCtdrCA7iaKouJ0Q="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj7XfTACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrvihAAkF+d4iiscxVJS65PVH7RdYBk18GSZIdIwo6yECppNnNDVdrk\r\nEIkiqhcjafaIR2IWwb7/5agPmmoSsIk+P8Hny+nRVaBss4rWzjOpdoACQ+bB\r\nxHJCx740oIKy/fEW8KfqJjjRKI+WMTegrRgBpEMWyje8nrcG464rhhNmecRc\r\nG9MyX2uEbzGwCGxiElZLWTVoB8Cx71tp90c//4nhFfPgKSpv3t04/WMogjkF\r\nqbHUAcobEL+2pqdIrE5JyMvlDEY4E2+BWKcG55RWmNO6KaUHEfw2/I6LGg3y\r\nxDsK68fTExYLFRjfmgh8RH956G80SyONyR758D3Z+QBKirjEblP3aED0vaje\r\n/0CmJ/GaO3Ek3K7/6HMJBZ1cD0GfSGgJwa2p4nE53Y6l8jcJoZWmUIYSDs21\r\nmwzH7uPUcFqZE/MOpol8mFhyaWK5d0c0WW1HvGgoltQIkzCjQzInnwNTMBok\r\nOt0Y7mIAwRG+VDOm7eWQ7BMIJfaWDHYy07iUnM2igE1b2wKXLCE8y9wIQz83\r\nsETqajr0cziGzgMBhABO4qlQis7DFl376HvF8p7cUZarfS00Zw5HydvVwqd5\r\nsxOqbNa1Akz4BViNAZJSA6u0pJghLB7N+6W9tAsNuRBbf6qU/RBhCWEhIten\r\nFnyvgT2nzE4AdrySgstEoyoSEbW36MLaQNU=\r\n=X0Vb\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.2.2-next.63_1676507091176_0.5699703985780802"},"_hasShrinkwrap":false},"0.2.2-next.64":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.2.2-next.64","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.2.2-next.64+3fb3d3d","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"3fb3d3da768acb48dcd9af13e56e84815f37613d","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.2.2-next.64","_nodeVersion":"16.19.0","_npmVersion":"lerna/6.5.1/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-Jw+RK7CQK2tZtggjMrMejLkxzOPajOgsdyzMy5W1VTEru+KHtpVzbdWMjt58quyzcRUAanRJr1NdpkWbbVNePg==","shasum":"9ceaae5ac13edb4c01df8772409829337cfc5eee","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.2.2-next.64.tgz","fileCount":47,"unpackedSize":372766,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIF/fEvLEdHeNK0kCkAjHmyIsofCmw8KGYH8NBmViVXQqAiEAgLCrK/4T8LiSaEfGWjDCWPIrO2VIRfblwsmqyg3Bm/Y="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj7XotACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoQ1w/+NaeZP1Houru4mQBvOXEOYGwLlyC6QGZIDYPQvPoaB4QeuINC\r\nJLbfiZqymAwbzby/1Qcsqah/ghC3TC1ywUuVQSI8j5ToLLqbvkKaIXXBEFoH\r\n14A6ZWJ40h2ef59u90/k7q95OYUrEQmWCx1j2muGziX9zAhITrMqOLNRjwd3\r\npDwm9JSTr20ZGIDjbYSwm4fz2zD6zyqYbvoDLvbPRasxtVfOJxecTl5Zhm/R\r\nSnGBTwK2r8XqBSo+dQfg5YufhKJqA8V9nL/N3F8xThpUpQC7R470zbtpkOBa\r\ne7q/nEPzBUNkGbet1C/CpmybUOPnZpPw+SJ6TyXO9BV10qvcR+/w3bpojtno\r\n5XYaESKoukDf14FbVkXVoVORg62MaMhx4fvpW32NXRTabf6tCTFq6VDwbDUs\r\nznDSjDpsfGii5hPKmQK40uMQ0P/IgvoKmGy0INJwyZ+7DYNLuhiGTKd33kEs\r\n9+EoPRg4+FeUdN0/poQSOg9h6XOJkfwvw1OniQ/irUvL4eJ/+4c+0oVS/p7i\r\nShNcRSYyBbCDJb2jJNgKc9mM/ImO8MEIrlgTIbkutaL/I74+9cuV1NbFr0xt\r\nhBW5qqG7ZxZWHpZDh+CxVgkXRqzxWJCKY6U3YXGQeuwOGckApukcMaIWI4gW\r\nYO+Y4KsMMVM0epzveN/K5zpEUbQbp+j2ii4=\r\n=Lht1\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.2.2-next.64_1676507692785_0.03586242988848731"},"_hasShrinkwrap":false},"0.3.0":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.3.0","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.3.0","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"a38daa3af472c44235a8db3e93aa91d18ec37456","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.3.0","_nodeVersion":"16.19.0","_npmVersion":"lerna/6.5.1/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-yniH711A9XKexD9yhb+bxNwA04KGQNY+lQgu5Njbnutix2Y4oc8cvI+csWkYcs57OlTOvq0snHaBIS2fnr7A8w==","shasum":"0880e1cac98679eb5e5025b53e3bd7c4d3d2a733","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.3.0.tgz","fileCount":47,"unpackedSize":372734,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDTMVU2PEhu6hzjsjRo57SUwqmk/cixdOLFgD9vicnUHwIhAMMUTFzm1S2o4RBKui3oFLOtQ5m+vXiSOtiM7ZB+lcEF"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj7XtXACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpCrw//Txfn15oy7X1PnlkQGzHkLZDE9cpYZTDLct4ofbpyA9XKCfOe\r\nPZDTTJWIs5MQeeYMh/225bBx2X4yC/5FuFOlxlvmC5ojmichOIK4GAZ8YJPX\r\niyCHNrE2XrpmXfsC39eS+qgoRbehaCEF+2A/6CgtvFaMKcBtw5yZA26lhVIj\r\nGKRR7bvQ3617wNu2zZb1rtJSM6hPM+rK1HWQUO0vxSUFXSoE/5rpkWZKcqMj\r\noutOFqdrpJxqXYRIJ+MRer5yRBNc9pkwQzxcMZlYX6wAVLyblKGtPxsglt7+\r\nBTi4YpNVfwUl23LYBWHFVSwCNafHJanf9aHYCp/R8CJJpygNesVxFfw+mcRO\r\njpOZXnGXLbJIczVoFZ0YczQ3EUwWa4TpigniTgLwohEKjlTCjkQbiVhSiS2w\r\nWYM014YUKAVih4kOyRu4c4IZIwGlY8rEnfYUWGpaMkKScKz7GNjS8jpg37sE\r\n+5XditqrcYAIKKRla4lrrZfaTcdQ68XBY82xbMdlENoIpGj3TEUUia6Cn7w6\r\nCf4K1cO9Ykx/zIvhUVk+KkJYUBzRvpNKD8Q/9DSY654WcKAytqFfNTIEfYR3\r\n3TivNCsRIpVMxSieX/vA7urneAgpZZv+FH8nQWsv+yNMIi2qaBHcnpKYLCET\r\n7n7oE02Pob6dXORWMNe31ngdyZcsLShKoU0=\r\n=qjqB\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.3.0_1676507991565_0.45563390258815173"},"_hasShrinkwrap":false},"0.3.1-next.1":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.3.1-next.1","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.3.1-next.1+7e2c9c1","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"7e2c9c18bdecc9fedb2c65390db202452ba62633","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.3.1-next.1","_nodeVersion":"16.19.0","_npmVersion":"lerna/6.5.1/node@v16.19.0+x64 (linux)","dist":{"integrity":"sha512-f8K4pS8GQ5YKPBUMyPg1Co5T1Xc6TeHgoVsfhgzWTyeRYhn1RsIw6/ViI5/m9tEUxGcGcxC5iX4H/HzoaloyUA==","shasum":"00b2eaabd51d9b15e331f837b4753f09364079d6","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.3.1-next.1.tgz","fileCount":47,"unpackedSize":372764,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIAxsGDj5MqshByKqNNlU8iBeW/LGT8PLrFTN+wqI6QZ4AiEA7i/TgWiQcAzCQmKTWRg1OSgfAWPF0s/TJ3pn4UxqR8k="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj73SuACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmomgw/+Lv5rsk0D01a6cGm9TJxFhWqk0YyVMpXGuaIMZYf+n+/1JdfQ\r\nuPkRiJdGPrYLPig1AEac0qY+ldgKdLbxXsKgQgN/EIZMfrdvpDRePhoVXHYt\r\n/f+8vgJtsNDA3Au4dleT1mztvW0hghI5G3PsffoA/yUzIp/OS5z7+d/cLGQb\r\nuuorqtl26WOCMWkaylW4lUtQ1bMesIZ8YY/tKExe++UJ7obOUnR3fVrTTEX5\r\n0S4dvGH0MsHZxqeXu6bTjNJ1m2c4qlNrtpufca4Rff3XFMhHVZSJZ9lUjzuU\r\n7AwfgmCBglqP0W8kV5ulgehsM41Olf62nwDRJRiQYrqRm/GnhwzXJPDAsjIe\r\nOu06EUFzg41IAvrOBf2P34XlpxzZumtqQCf/Orpr7SI9h1FybIVvGXPXLBTR\r\noHL8ZuAlbOvKDNpO1AfajJ90zZG56r/lfN32+M8k+nxFVxtWZUwuUUopdmgM\r\nfsQd42NSd94HiPotOd7gBi/zoH3KsiKMraACfjufUmQiGw4DLs/HIL742ZHu\r\nfMVVlxyDDo/73jG/Ql6A0OeITe4ro4d+QNSMpVGo3VSort4MHKkj/9RCrrXH\r\nqx7AHmR+SthKXREWU6aYPNahIHMBvI4VcWYrxOAujOkUnbZcgVH1yNw825Zx\r\n4v1q0KLA+IFvb2GsVIGVTwRzpL/rnfiXSTI=\r\n=ZI6W\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.3.1-next.1_1676637358655_0.5411091795263621"},"_hasShrinkwrap":false},"0.3.1-unstable.2":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.3.1-unstable.2","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.3.1-unstable.2+17cf429","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"17cf429bb2afff11b45b2a0249695fd735280c80","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.3.1-unstable.2","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-3Tbv4Y0L8VcEZcLMbVNEh1I3ioQpOOFneFrh95+Fs4xXTGsEDCV2/elY/tQ3bfkes5fKQFi3FvT+mR7VEAYOlA==","shasum":"b7e6462af5f3aae425233057d8f1d9b83558f13a","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.3.1-unstable.2.tgz","fileCount":47,"unpackedSize":379231,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIDYFdmdDG006a33Z17Cdnttm/LTZI1SdUTkKfAadBFBGAiAt+yUx0mQJjSXlgWlXu0Ni2238eK54po+OtsWuAfMzYQ=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj//TLACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp0LA//WIkv+FOAYr2stp3ERf/jlmbAOOhncqGKsu7PQATW34Tw6O+k\r\n9fciIDaA0Ezk+5UZFtH+uBYargChSDBfzJZZ6tPm0C2RvV59lXm6Vin7a8Lu\r\neb7OrvxPPCOgo1BVTdh92YvgMkOWpWSdb8Bfha1BMlMudvEN53fcLMIq+oDY\r\nZ7tPh5DblEVGiIgzohk2Tm68V/qyHt9XRZaxRCYwX+Go/szcKDjG7oCRdLmp\r\ntSpqhI91TX9i1f1ed+BQgYXZVXmruA5cnXPjaI5msWyHzmgS5FP2VB3UZB/s\r\nAV60Wt4c8yltp4FXf5IeDEU71OLteoItb0MdwEHsUhO0jUmDiZGunC+eMh1x\r\nYAUoyqbqryroDKtne4hxyz9zhrKrlkPh+AJKbAdo0X6obxAdYmDTSA/uZaK8\r\n9n1a79nd9NYouuAT26FcQL6Bs6Cd4h3Tevcatt7fHZWvMDXDcwPfR+j9gzWH\r\naxagJ3fExujQUpz2zf9Muov9lkqdfANl+iU34kVP3yBXNAknFJ7PjksXQTam\r\n27xvMkDx4VuQmbJkGS95ebvGXZm/rYnmmglF76UdsX5n/i2zhZHRK8RuKNKj\r\nFMZtLq3dks8r9HPBVed1WZcEy/iSHrHkUiweVMFZwEeegZbeDgzbp8F+OvAS\r\n+++ifSOV02UbQNkzp85oUE7EcsSklE27X/Q=\r\n=VusB\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.3.1-unstable.2_1677718731228_0.8155905128997201"},"_hasShrinkwrap":false},"0.3.1-next.3":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.3.1-next.3","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.3.1-next.3+aab1cb8","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"aab1cb86f95310f955da83a6746cc0e9d2d6dbc2","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.3.1-next.3","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-8oqWZ2eJPbfkOmO6ba/wG/pfUzZnaJ0PwfEWbMaC4qUa3g0GElHLMDi/uxjtTq3YRArzbCCEmYxstIks4PiQLQ==","shasum":"e6c3eecca8f6f9178f6d37e822ba71c42e24ad03","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.3.1-next.3.tgz","fileCount":47,"unpackedSize":379223,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD8wKt7Gr1xNvCpCOdR+jYw1or2XtPycjrpX0+IitBKlgIgCmjfOHAy7EGHeU1xTAfaLUD/jkjlDgtZQg3Q9b+gdLw="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj//WlACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqVFRAAgBDH4uj54h/cWgnmT3+QPd7PJ4ZCbhkrS/9Tl0304iPEbQDv\r\nfYTKGU+os8YHt8jPvaVIQmj12P3YrUESlaCsnlJ1ReAvtIvMp9LMe0oZjhcq\r\nyrDHK3GAnAexyfT7Dc/xMKBZPQ/rl1/mkxlod5LlH46vPoIHODWUVNTC2eVF\r\nDQfVhiGzcrtHe7wq6BzxWABNwZXX8oQbYB4qVtU1XG2rW2DwVf8iq5WGQLsL\r\njX62a9mITbRL0MHcJiLeISSQM/0vEbgAzB5y4EaNP8DJaON75sjfyKjpu53H\r\nzG6XaRQjruOOA3KprE8dTarBLeI+KhUej283vB67XY9vYATibItwN4/sqMTt\r\nCKy8RE9bEVYRqcBL1gZdOKONnA7uyEaKu14QXN6kihnTdILYFC+H8JxfBuku\r\n7H1p0k0nt2pqE7g8NvWW2z/d3thbr1BJkn3P7igjYSWKlOe2m0j2vElekYeT\r\nerXPsB4wbCkgZ4k/qOmHatBnnbLcK27zgMqU83xhPNwElJXxmDrQLCrYoVWT\r\nQkM8S42rYndqPoFVB7y/Za85DCBlmJuOVH15K/LZumXCtlMuSFy04E930xQu\r\nJ+GD9RyyR2yEfQpR+xCaMVtWn71JPFtiOIiPI/rQrqMFeNm67T1oobwtr+ew\r\nch+IPcbHcii8p6Hx7tgHZSohsGAKheBFqYA=\r\n=eMz4\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.3.1-next.3_1677718949561_0.8451021650335644"},"_hasShrinkwrap":false},"0.4.0":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.4.0","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.4.0","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.179","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"bcbe3d4f1bdf33be34a4bc497dd92211f10a78e4","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.4.0","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-DD1cMP66EDzaQN0f8NMiwNP+IVjqFdeZoWOBTSqMxuWjrjcejLPGwiXCvYudGFCiuxrWHnNZqitclEKP5Sc/Ow==","shasum":"31369329727d498a8eb782cbd3c9ab2589ea6afc","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.4.0.tgz","fileCount":47,"unpackedSize":379193,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFng+wk3/V23D3hJBG5DTgoTS2xCAv4Z944FmNgblGlaAiEAzehIaWn12eKziH21WUE/s7/7muOGpx/q9Mifu71Gwbs="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj//g1ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoMRQ/+PlV2A8ONZ2jeeFdvZIhaymB0VaBjrh6Tds4biXbn/rGAKZKu\r\niKnSZR4v0gtwww6LsCWTaH7G4+GrrJqC8MUAskeSzgH1721sjUTjTPhFAF9I\r\nkYf8wSGrNMVzCMs3dLQ5pOSJVJQzeEdGSajFDLyFkwM+18vr7uKzdphMMqIh\r\nIrp7EdmexnVt5/Xs1Q4II+zkzKeWwN6AIUSnAJFcNjU8P7Z+6HtG6yoqAHfd\r\ngPQb5MRCkNuvzNi4qAGCRXxuOhIpUMU1QQ0RkPa+NEgqfDQJVLSRFvbhjVwX\r\nr3V1y+HAQOarDr9nJUPCblrWt6t4nIw79YlIJiK3XCOQaN5qij57WrT85lC1\r\nfnAPjes81fC8mqRaaGbppO7WuM8utOI3b8oFqkVPjm327z/OKucKAnYpefKc\r\nFOLKD9ST5KTvgt7qlMhSega5M/ICuxD5YEokXeXavi3fGtfzr6Ee9vzsQjby\r\nzVWKqMCjU8w4zurcv6NrYxwUls5OuT//+48kBHn1oiaLBzhdicTvcDKon9dF\r\n2brgnoUZ2JO0eNnAWt59a7pFO3RiMQSTQib/RgLOr/YoRJPcafMwxqfFsCNF\r\ny/DKIDRDFtR6A4JVIusMPsGmjLGmmGoYyIsOdhpV5t+yEvTQND6iNpTpUzcG\r\nUwAMHDHt4hHWk5OlTVRInESnKLNklc5dgvo=\r\n=m47j\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.4.0_1677719605017_0.8708628638667939"},"_hasShrinkwrap":false},"0.4.1-next.1":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.4.1-next.1","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.4.1-next.1+6a1c1d0","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"6a1c1d0880e39c7279dd5c0206e0df5345eff0a3","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.4.1-next.1","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-oPx9MT3MOJskU0rQHw6AW4OVr2YRXGLqFLTEgboStmFTdnvni/ggwvxQuck2CuEYLxSPSipljZstBrzCUYjkBw==","shasum":"37308af7519ae121f7a1e60db68c28a5f8dac01c","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.4.1-next.1.tgz","fileCount":47,"unpackedSize":379206,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDxBgiypvZxGoz1PJkjnU2E1jagX+mb5IPhMxb/C/yqWAIhAJDtaRbTKVRG63EihU1yfZJF3u3mj16xEzx9VyzqFSGk"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJj//+eACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp9jA/+NS2PF0D7pdLwh0WJtgqV5JxgkOhxvCMour0aH1I0A0VqA+Bs\r\nzQY/hG0+VLGqwUpAMwkmLArQVx+cfjnwLKgwGrFc7le3p2s51lTvPU49pHEz\r\nERDjuS/WFlGdDtuM8NCkXnNiCMq8MbdXc9prl3ejWljnM3X5vmLrgVbJYK8W\r\nj++9K3UMgia6WFyBdhgWlqHMotXLh7An+PJnq73jhFVk2FAsI4SNvHTS/t+Y\r\n/odxcWSFY8MS4nL0HQgquXg2ddydauLwcHel1Y2rd/NXqOAjbOhsp6W2JntZ\r\nfP5Wn7wUTindhORU990b7831XXJ6OHO6oyKzIHCrnhV1jnTBeRRkev+teLMK\r\nTR5216Mt0OH+MoMH5zmh+xhcKSJCLpZPPDptvquQUGoaQyJJVtExWsR7RDQY\r\nB35egufGefMspHzSrc5MpuKdfQ3ZHj2I8CyIkOKORdtySZFinV0kt7aSBvjc\r\nlnABVfLH4ZjV2XIF1vuB4G8MZZPzQQsGvQR/I7zj2nuFQrS3qekkhoNWS8/G\r\nmZz29347519oWWZjwtie7txKLDYFI21qUlBesymzf9AJGdgkMZY9ObaGiRIf\r\nBoAWo0YVkltO+BmM2wggSrLYTxHuu8ElAu9vSsrEEvho1vf7SIacxgYzZ7Kc\r\npFJBjU2/ne6W8Gs7DmP9Mn9F4z0zAHHwa0c=\r\n=WuJV\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.4.1-next.1_1677721502556_0.6796556127078994"},"_hasShrinkwrap":false},"0.4.1":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.4.1","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.4.1","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"106f002ea0afe496a028b8aa2b67e58a4160f3c8","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.4.1","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-+1nbK/c3cWUmVfnorw6fWQcowIh2IVBojcXa19ytzM6jeteYPcm3mvAQWURSJtb+CmYoHm4GVmaktjfMmWIi/g==","shasum":"b8786319dfebe136afbdc154de2367d6586b07bd","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.4.1.tgz","fileCount":47,"unpackedSize":379176,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFcoxZTj+dyEoYTx9a/jiGeI8AKpbfNBb6U+aIiwxuzCAiEAog5X8pF6w7XuvxqfAxqN+8ODW15kwISwO+8fPIN5gNk="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkAAEVACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpQLQ/+NUp2QWBau4XXPjK7JbM3PiJwoi4APcVpz2l1Dq2cYs1Wqv1g\r\nHLoIuk3OeFwjWCSYnrDad2cx6ZDP9VPYrLcfuNrKzDz4tdkn4d8WaCU/yMEu\r\n+EevFwJCKaAX0q6Hf3hH0Es+LvBlTD7rEmyP5BEjcXMx/VAHu9Q6Dh/upogy\r\nkH5r563NRv8Zo1yc9sS6ZO71emXtBXV5GBIszPHoZRhuy1d7hGKDJ3LUrB6y\r\n6Dn0eqlDmw+YXXpiX3GImsktBi5nDdgvHuIh35uBRYNXD++6cIsStF0JVUpg\r\nySAd+nKEDl9o6jY+8JHwhFSfyQQxOEBcNJFmkLAI05rpnd8gmFVned+2TGJ3\r\nMhqwiWsWzj4TmtlXeePJmCzrtk1X6I9WrZH5FWCEJX9xFAvoV75guENllJRf\r\nMJNgIV3EDmGmdwZGcyuXyxKy4sb3MDHkbNVoZrRXZPdp5rDIBwmL2a+zEef9\r\neBdaGOrGfIchSu4iZ6enwfJm8ia9T7p1lVmBXATfUe8X2ibqbF4uYvCAsVSk\r\nO2fTuk+hosgNM/3A8maVm8sWyO76YBY6Aoce9CCo/t9FuzuzixlFfiKvScpd\r\nAm50diPBaQkoYNns8z6cAMedfGwkKcNDPQo01XXz/cwW/1iUBJvgK/9RNy8O\r\nSjVSI4jL+swsMITgvrwNC27qJdutG2pUYHM=\r\n=q/rA\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.4.1_1677721877335_0.6633020445044735"},"_hasShrinkwrap":false},"0.4.2-next.2":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.4.2-next.2","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.4.2-next.2+b7f763d","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/core":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/message-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"b7f763d68abc42918813ba8bffed1450d22d70fa","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.4.2-next.2","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-f0bIYGvRkUFZR51alozdEh+3WBhKt6PM37/xM0ZGgLDupTC0N1wj4djCpRr5Ug33X0PVHjdgDPyYid9a1MPjmg==","shasum":"f483662ca3f08ff1102c8371be86fff35379f831","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.4.2-next.2.tgz","fileCount":47,"unpackedSize":379908,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCID+76Ujy+c7HfMZR8h1K6ACKdi1bHkJpovBXbNLXAv1UAiB3V9ToZ46rxVXGQUUQBioA9RlfTG50CgpHeWZb4fIM7A=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkAALyACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpvYw//cPmOGbsGN6OTbwy2Jw82hE7N6ZAkIT+zWFG0H8EMdpRHCUnL\r\nf8Ar1iddX3BqYyvik4+K9UF/ciRyXE9kVZAeLVOqehJ+Q9iUJfsUA2JAjCTc\r\nSpmmZfV8i6IcwHzpY7w1rRFE5jDVo+V4hbduN/6lTsZI8emIYJELCCUiWZ9+\r\nSbWClfCvR40oPMwRUQw/5WvvRQknWffjD6hwRA4ObWgpTar8aEwd6DSNSP29\r\nc3NRNrnOTBvrCv2ijgpL5PKuJhqUlRNOaa7ys8QHqw5qs1S52ISrQ3p4g+y6\r\npz8ue1rikbNhqS0BvpowePJRqQ2ESDBQ1NUS5rJXwekrLxKjuBqrCnCr5Bf2\r\niO+fI2K86tml33+vYnL6ZDFBqbwj5wWjotQyZpXbYLr6KBMkHU1lxNTz1DuX\r\nJ+EjTCYj+JRgEwkrRhSu4cDHfTR3csta8kYM501fXwYEk5fjCn3gDqx52GeX\r\nhrtIcgkASxOxI2FPie9ZAFsyakSFVBw/kPaDZTMN/Y9Tx3ZQfMM5WozjHsmV\r\nCG5WJvsBkoTtKntrUtCIByy1YX+gvUa4CRPa8p+nWiV6mt27ttClyYzpAxAN\r\nHrqpMF/aITFrfc/gahakljTuzEsGc4tVltxS4C2dN9uxVM6TVhOdOXJK0JS8\r\nukRHWM8s69U+Nz5zQS2c4Ydp3gZkyBpyKgQ=\r\n=CXKB\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.4.2-next.2_1677722354033_0.4544103788655447"},"_hasShrinkwrap":false},"0.4.2-next.3":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.4.2-next.3","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.4.2-next.3+828c0f8","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/core":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/message-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"828c0f8f6d456765e0d6a4c0cf54033a52f823ba","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.4.2-next.3","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-h/5vOFa6w3/Fw3CXa7GnaB1fipyOzjYq6t/EunOG+f7AVCETEblFx4ZQwbU12DZomjdodkxHFsFoJUmS3AWnoA==","shasum":"428581f7611f18388e2e675413ee2ea6c2408a23","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.4.2-next.3.tgz","fileCount":47,"unpackedSize":379974,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCItI4RYorvQp8iq26HfgSOuTLvV4fybP5keJ2UWxEhSwIgQ5v33cnMIrledxDDBXmU97wHMIF+2qATXpi51FxogKs="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkAAUVACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqp6Q//Q18GIvQ3KwF2czDOWfza4O15nP2ItRNvIrB4qYaQcfO2vXyE\r\nR5NdEoQLNthiR8kF9+S9bezYICLiRvXqg5WeArNKEejtxUKBNZ8jI9aT0Jmw\r\n6abdco+EFmqTkX8tnU9OPOSXwXsIF/5BmQQYPCOkL6Vap71aRizFCr+UZ9IP\r\nGT3aBoRb4DXu0hdjf2eJdovofxfZBDbm+DJ1vgmEY1xQIgSY0NqaLZPGdyu5\r\nm6h6RQha06WizDO6P933E3cSuszytx1XmGuzUeB6b4c8tXXEfvqxvakFmFjj\r\nJ8VL5BlJtyPXFwVdJ7i8s9l/FTfpL+KlInjwRAWL9tP0m2Xno2O05JM/VG89\r\npbS+stXac4b/SWrZPzvpVg3E5acr717HOUKQnTd+/qr+Rw90fhWv3h/gXVNm\r\neOiExNhugqqE27v9tT2kshuO+lVtObls6JGRlqX5h+VyqeKdlEiS0sWFEe+f\r\n9T/xz+Kg9wOIrlCfDVlGdPk91076nJEVItKkO8EDdq+k7zaUAEjOLTJyi967\r\njywg4pJOJzkoDe0+30hTDXVqVy4ekPJnvHpwnZI4qrjsPhQm3quxvrSCPqo7\r\nKA+SEcCVfbMQLjPdEsUXxhiSD2itlnNnjDJzwpBZneon7WpOjPEnrUG6qbMj\r\n/1MTcX5xZh1UwD0AKo1ZxLfYY7WZww/G5Q8=\r\n=Xdwq\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.4.2-next.3_1677722900936_0.787035234248785"},"_hasShrinkwrap":false},"0.4.2":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.4.2","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.4.2","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/core":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/message-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"97748ee8d6d1f3300c4dcaa541fa755bf6f09ca9","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.4.2","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-YiNikYlOUC+aTKnShg+cOX/hv4HPu4oGuLAvmwSWoFUAl5YdTBchWvZwCP6zDuKoJRQ42EAmHEV/QdK0B23+lA==","shasum":"7f325d22e000298593d74cd000bc62fd4c9c835e","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.4.2.tgz","fileCount":47,"unpackedSize":379944,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIAoDfe9ihsSZ3SM/TQGmk1pYkCOxJC29e44roC60upgzAiEAj55LNNZjT4cZ8wnj7fFhjr5UOnQo8aLX+zF5LV5ap7g="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkAAbGACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrHYA//fuytdsACG1bTeMlI41JY3eNKwxsjhVoomR4KCkFvUkvMIVto\r\nWZrqhHDVfXW0Mi+OI5Q6WFUO0uqKqYdWzYCkDRnGv4lJYchj0GFH7bOiZRdp\r\nkrkikIFOF6hTT7VL37Fb1ZkfOtiVIMxSsOHLaAMYy6mLhs6VfLqQZkycARPB\r\nph1AdZrM+M7JGwKhs/D8IH3UQ66FGs15dgf+w9AgtUK8LZYzYo2iQRGvOV4i\r\niqBe8lzrdbagsVNd6tZtkY+V9IV9i4cvodPn0tTna5EeJOxe7C0ZVrV6kP0h\r\nwz5CHDzu4qCQ9W3cMAsmpQNBPLeG0fVcl0N6DBM3A/Ed8EDG6JS/RsynKa79\r\nWFwc/T1TPAtj6ylmJZyoLrdKW3bxzwLAjWxOfrqSCxOVQIdT3826OYFMTHZd\r\nIGrbTpR20aW3WRfJXxKVSDEsLW/2G19vk+F2/DuwPi1+WPs66PtNFBzdLFb1\r\nFBDCHg6IC5J9GVgtDakAfITPWuR3GeADEGET12YbGfuF47yh6sNIB3vSr3eh\r\nl+eomLYX7++mummqD+v3GZ0Ou+dQefi+GZV6q0jphpKDEWfEswZL1pcA9tN3\r\nBGTKw4evGtEbRT0ojSzA7723Ak9+s6XR8I1D5nuJVZK0piBCbpTGO0HXdlK5\r\n/+tZyOilETsPQMXaLcmVVwDtxs2mBmnGXO0=\r\n=hP+B\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.4.2_1677723334395_0.6528142177422978"},"_hasShrinkwrap":false},"0.4.2-next.4":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.4.2-next.4","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.4.2-next.4+73b62c2","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/core":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/message-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"73b62c2ef31e7f29c265e0ae0b7caf35ad4bb7e2","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.4.2-next.4","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-YiVxMxh5A+SmJBGSS+QJ0HVjSNN/8ZLBqDHfNWZzBy+Da5OWn/nPvWEt94iN/fVTi5Hi/yfvEgSqPMAFS1FqHA==","shasum":"edd5f4c8159cc51aa6897770a506f2d2e20855a0","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.4.2-next.4.tgz","fileCount":47,"unpackedSize":380092,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDSuiEEDqWRM+9IsnMvKzQOUEavJeaMN+7zmNPpLkmw8AiEAqbf8/DVy3dE5O7hR/xDKQnmtNoixcNl5tFpR7As+hQQ="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkAAouACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoE8hAAgk53DeEKHYJqucV9mQTVipdURwEfESOu9mS80FKcxgpgNioK\r\n+3RREqE1LPTBkFl4UGJntgN6F8DKXd0VN4bFjdApny47/kUlzK+/0ZUAK4Yz\r\nB74JSym+H4UzHwwbZQr41Ml+cJUbKYhz6EoKWcQtS0nj2ihiRRFRId9X3Ncm\r\nMbKo1JpptUnfeJH7ZL/wg28UWT1g8tlBR3vM02VySFftfO3vDDgUXVeBpLIx\r\nAv0Qely3hUOxFpfxy2MwN2WmCOeUufL+RhKttTmofyK1rcQcuWq6xe8oC7jf\r\nbvOEGVVGKXaFEpU8s6rmFgupnlt6lyAekrl8vUxbTiAvESBojzUqsNFmhLRC\r\nWnqn4EGsRUv7VwCHvXeD20xPf6u3AO7SYagyG/vLJiEFrWbleSdoV4T/Rxvk\r\n4eE16p3sX1CyPxKa6RHPhxNvYRoCuhlV0Fa/RYpHaDBKBQ/I4qmPboS+Qa1O\r\nHmp9R3gMu4tCU5g4Tha0ARawy6iskwFhC4mo6mGwIglAs2JVC7Duk3dSggMI\r\nkHu+xOXxL9qECUgpqqMb3zExMtzCZsdCZZcJtLbqsKV2WRfIfigg/hgpYLsA\r\nAc5iTBpz/FRs5W/MKuGX017VzbHnN662/hmSxjQ+2D3tzzN2WnmMFmMzXzqk\r\nghYYJov2DesAcWhbJcC1LzSnosvbHjhFedQ=\r\n=/rXl\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.4.2-next.4_1677724206704_0.8793219386406488"},"_hasShrinkwrap":false},"0.4.2-next.6":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.4.2-next.6","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.4.2-next.4","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/core":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/message-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"e65dc045c38b215456416fd83367f6366f70b088","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.4.2-next.6","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-ui3l2p4bTk4fq5OnYf1Nzb55sGY2WVyEFbHzZAuWuqTuqKQt8eP3oF9XDBkVDu0DulBrDzYBKVsUjT/+gN3K4g==","shasum":"51c2ec6c73ac925c87122a5710becd458f4ff408","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.4.2-next.6.tgz","fileCount":47,"unpackedSize":381630,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQD9+MNpmlnvc3OxDrfCRzaRj1wbE24JT8BQGpG1H2Ia/gIgBOgmV4g1NLXFQzbILMmaD3+ZmU5JEXhIbPHO9T+j7M8="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkAAvOACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmongA//Q8uZHUiqQrKqIvRYr6myDONAcD3eT2yKKh4olmaR70zr/hEG\r\nEhoOKEh9X2PUdxDLo37f9BCEVPnx7Vdzy8BESm2Pvc7fxU84M00ApcZagKCB\r\nexikBQT4sC1xpMYtrcCHPESMXFVgKLkf0fV6KRt8JUPx4mfw+BR+x9NcQnqG\r\n0Ri2nu3OgZ3elUEFqqM46fC1WFee3bdlJ6UQo/k56cDNdQ5bVcw5v4vLsBsB\r\nixCn1zjyTbq3kkP/BFEfnEqlm2RBwNgioCtbmxjsbzUUFSyEZS1PXB3d35mM\r\nTsyhqUDJfK/kF+nBx5w6mkp3U8xiXeWOj1V7en31UHOstaoHpSSzdfobiad8\r\n3kz4VO8QDB0qVEZkOgvAuZu0JSlFQcRe+mfjOfTLcL7PyprZktmigYC4QBb7\r\nVwJhcCIJJS1/5WKzmwk6e9iqijAJiZX6DGWoca/pioTPsHEMSK6oChw6GVEJ\r\nVk2c3YA/8vcGY1JJLVOvX9NEtvOCu5D5XDUSFV0cpb6/rsDerP+F3Snh8CJm\r\n4gy1TFcPz2AEYLSRYIOKSoruofPY6gLKBGbz9Vt234eCLXRj1zzAr/gvcW1P\r\nhMNiicvpPje8/Y8vvDUITSwU3bsKpzZ4/ouLtvOq0KsW0K8qZG67zTTS/waP\r\ns5WkjVUuul4JGQnftu3GVYENh301WCHiptU=\r\n=X5y2\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.4.2-next.6_1677724622385_0.20948704086991166"},"_hasShrinkwrap":false},"0.4.2-next.7":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.4.2-next.7","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.4.2-next.7+6cf211a","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/core":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/message-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"6cf211a316c3f8ab046e8467c388cd41fa3a12e7","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.4.2-next.7","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-wj888FWK9e3I3LvZbqqJ/ILwRjLcwXF/01aoXryXMbKPe4TZXhITUzw7fJ/jpjB7lF52EiqS0eL5gWlrNs23aA==","shasum":"fcb64c68b8aaf51a8e6334841cc29517c50d7613","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.4.2-next.7.tgz","fileCount":47,"unpackedSize":381638,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCjPyZWv1JH4kxhGjorKPmwMlVKtiPmYt5Ucz+5kL3G3AIgKkNmaOTrfrBarEjcc2x26NeHDtbnnUU4JQbhVEzYQ+I="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkAA49ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo6qg/9FidZkOJ+q/WQNGmRStX5DGxG/zXmhM5IyAhoags5OjWRSOwF\r\nt4no3a0Q032nfJx53OSM0IGlrK36smwn3R8cdSLjh0N3wa0boOVeEIVZa1+w\r\nAXK2wBliEZdnF5AqWZiL7DFk7C5eX8PvqtUUzvVwQzYIJ8ZNiDkoU22Qm2XJ\r\nTfERe4AXlammf6fjh/9C1dD3Qio7BARS9RCHUpECRhptNvctSEB/l85gQlro\r\n19nhFvXln79bHKchBreFVVQIIu9o4wK6FCWfqRjvTABDZRLdQ6pxNNocMWyT\r\nRc9dAkzjh6OLKO8QvmOKFzK3LCgSrsgSOkerm7SQ4rl2fDn7XvcU5wRN2T8m\r\nh3JjFhh0MaOsmMfKeemRpSkpethUBmWRzFclweIeqUa8DmHY7w6PZSpaLjlR\r\njFNnpRy52BBp0gKzC0eiGnFhsH/lMYQCmr75WzZlDg3Ik6ZnbSF2sMs2kxvl\r\nsbOPONSmTXBobCoExZGngFu8UiJ7caGYO6jskMDa4xCuuUhQFhRJGrIEAfuf\r\nAWaJ1Wq2QEnlv2CnUavVWygyP1faRgqr98JN8MydClQzMMr0QKT8t1MIgWaE\r\nfrVK8nmgf8uWoXIWPJFa80wj37l2ChHQES1umOsP+kXjcS0uR0eSDgaVnAe1\r\nFb5BaI8SNBx48WJGpo+tF8T4z7SA/PcSHas=\r\n=yVzw\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.4.2-next.7_1677725244884_0.7981032592517405"},"_hasShrinkwrap":false},"0.4.3-next.4":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.4.3-next.4","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.4.3-next.4+2c490da","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/core":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/message-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"2c490da1d053aeeece747935597177fe18f21b80","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.4.3-next.4","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-iRtm1zOiXdvtMrPPhhX1JE2UqumXgoGG+YWbgIwiXdOKMoAQAGKKb+NVdbE9ryW6ilMT+rjFPETaciGVvzZ5sw==","shasum":"a84d0625f3501c6eb5191ffae3c8b64e66d7d29b","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.4.3-next.4.tgz","fileCount":47,"unpackedSize":381638,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIAv9XqGflMC2ZtXLui0D8zqVxcj//6mCVo10U1c2iliNAiEAwzGzIqfKHRyOW4YlHOzAWvLI1vAtMw2M6flbNaxy96Q="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkABEFACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmpfsw//TgfbpmLFqQbCWaPUsMwigrdtMkOmF5ihqNIi9mvjXc3n70tk\r\nOx8/nK93iABkuR06UnsAZZU2FTstME7G8xVAxwKvB3ufOarngUJch4F9pi4f\r\nckZ5zZCjv3jxqPfISoVVY+n2GTijEnDtQR8KijaNL2CghVEW6yP97LAP4+Kc\r\n/itVLsvm9jHZEJeakjrS3+T5Ghz6ApSzgR3efjdTl0qRtGxX1WRXFuMIVQjy\r\nOkFfpMNnuHhZZ3/VRt2ei7FU6KjmExix4bSB0UI/BwQDoO1KiQPxHsf/Q3Mq\r\nBWZpE7eMI50umiOpQVYLVd5GywFTwzOHBEGoyAuYMHH5GZZ9QxAa6G/qh3Fx\r\n8IL8pxViJzsnpOKrexp3PpclwoztKKXb8ftU6ngCCDEQ20EWuy2UCUbgBuuu\r\nKascXRhqA4whsQfmzK0Ou3hy92VJEHMtk2+/u9b6jTVrP9hqocrFjPBJTenp\r\nNiTVTLvkCs8SXZaTfMEkY+Db3GytL9LG3GwJAauRlx1SMQ6E1UFt/JShpYMC\r\nei7LNfjfpSrpKNyfDXpe1s7UgLRSwYVslTV4t1iVGwI5yWtNKkTkhxjVWxOx\r\nHAc5uYnTIsOMoQHDNNwi7jo6PQLG4mUIIkCnOQ/8jNQ2zhGXaTXchqiUgvkD\r\n53WUclJN0ANMbGXx1C6/9lPYcCaH+r3fPV4=\r\n=5emr\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.4.3-next.4_1677725957601_0.8714074783334409"},"_hasShrinkwrap":false},"0.4.3":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.4.3","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.4.3","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/core":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/message-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"8fc09f4ee97d29b9f2fb54a35e327f4f335a752a","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.4.3","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-B5EjXx/66/zyBw2Nia6rzFUrrWWiMycrrKEcJTlWLh8+tNmKz2UpfhookBj3dX/C5KSwwDzG5yWGTAvbcJtYBA==","shasum":"9bc3b55a41682487d59c0aee7e7605e0d45879d1","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.4.3.tgz","fileCount":47,"unpackedSize":381608,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIESRWmufPfhxwgaErkZsXfyCpTdwELmf2rkYUKIpGAvfAiEA1C1EXzQ4ZGj4NV41PBJ0jinR8FXKZDoGcxraNrZIYSc="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkABHJACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr3lxAAmRgrYeCwD5yICHuSG2UO8ktoHWi5U5yLiP5twotD5csd4LnT\r\nIpAzs5H5iX9gAYi2Mq4sOKcO/vIYxItMgGcm/0zyY3hru3cuUsnMrth6jrbg\r\naCXrjZSX8LdFaTk8V5PbkGmPl4zcIOhzgbT9poSnYMhIiD3yxBUeL+du4N/F\r\ngHQmISFhJvUAXLU9EOwtEGmmTsJPlCgWBc/kI0zddZ8LktXY+5Gx9r6gUobC\r\nsWMAohjxEOUJjtHW+68dP5Ox0ICFceL8V8w5ljNNnZg3SvphG52kYEy0S4EZ\r\nV4KyuOiZNsySTjAWuoU97WrWoeH82H5zEDJCTcQDN7jLoPu7iTGJ/zHaKjxD\r\nmpXOH1n1E2HUmRFkGlIYxCCvjdbeIezm42/5XisCdW7yO3wNIjT9OJn7diGL\r\n5guBOMZQp3pBTbs1IwX3Xpm+0bRCahKUM2F4yQjSSSYXEGu7034L0sVdc9wP\r\nNLs9nmdFvZFr3+jr1/87jbJT3RUew9L0vzkTvtwsUk1yze4KT7aBOYO6M6TX\r\nEa1eQZOhqDD8yjmWKQdu6dt7JKyD/MnAJv6rbEKM3xfBd66wXT8uLTGAsV5t\r\nUOVAp4FM22Zi4vYXJ25XFL5dFQMmDFZMqAl2OrEyk+0kVcWk4axMaWJppCIE\r\n5WahIeLEswcfP05MSAjAZGOoOqtYXqknMUI=\r\n=pKpi\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.4.3_1677726152861_0.9753259325875654"},"_hasShrinkwrap":false},"0.4.3-next.6":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.4.3-next.6","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.4.3-next.6+8148451","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"81484511cf70a52966c5d76cc036ebdd38666bff","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sif ./service-offering-input-credential.json\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -id 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.4.3-next.6","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-uV3QzjvTaCWpJ6F5gVjjOl1M946Xw2gMMK2Fd7vvku66oVlLIjcaLMhxz/XWfP90/3d/c/hXDjvDs7M9uhjqXQ==","shasum":"b73f3dc34bb57b15ace44dc1ab628a52c25b892d","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.4.3-next.6.tgz","fileCount":47,"unpackedSize":380687,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGvdjJd2Sy6FFE5bqnzFUY82GxqBjhK7BLGtYQoypl4IAiAKwXsgxwaw7x2Iih13Ny+YE1rNOC6riJvjUipSEeWGpA=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkA/rcACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpzgQ/8C/wGOGdnja35Fay0oObqrogW1uLKM/u4YYg24p3agfBBZ0dq\r\n+3KjyIy0cJ9w/NwbvA4bN1p09lji0HnwPMqWEGYUlQbxNH20FPqi53shCeuF\r\nbqPGAgswrArfQ5WL2+tb8jQV9hNbAHURVvLr6biLRqTOHNX3rxmS0CrmnOWW\r\nQxz3T7+kF+s2TBk8guGg0uOvryn9Yizv6j7yEoZ9orEhOs5wxsE8YHE1A9vJ\r\nXhXjkSDln0q/5yGCP+teUttBhcUII/2CjcLK9Ll3dwGM4CYqRx0YTS/QeCt4\r\nJp4jlGDBEcunYB0fi+y6tAUmSSpx7UQQBstvYUp26P01jHnmUYoGsuC43mQn\r\nRqcBHqOP3boC+JvoX+6ut00kb1xsrMIasJLeVg0FMduMtvKgzFrnbebPO3JZ\r\nQS2SlX+5mIY+lUaGV9PISj8Annm+85CyaN501G+B4i9DaKGpzv0GbuoqQFSK\r\nV2JasMwtCShotIMRWpdit64oNP2poOukt3zUB7g47ptiuDXSRqEEW9i81tCz\r\n8mmm+SA0JXDCJnaFFBxy8rA+NW+AXTR90XpfHYWoq1iZ8Mc3lx7JK8P9JlH1\r\nMsq3Ixe5L4WLP83bAMdLZRYkVL0TyMVVSlOkYV8Pq3SBeMguKG1uL9lkWRec\r\nP3M+47vMM4RrLXsubZQui/cPDGnY17A8tso=\r\n=14Wk\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.4.3-next.6_1677982428748_0.14669879978612999"},"_hasShrinkwrap":false},"0.4.3-next.8":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.4.3-next.8","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.4.3-next.8+a80107e","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"a80107e116e8fe25aa36cafb491ed1785f9411ed","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.4.3-next.8","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-VKszaBPIVidY99KQcopTPK+jy12T5wRHUpD+26WQnzQcHYFCXmcSFnljhq4aNbWPIKfxO3V6DAmgvh/bYnJLng==","shasum":"e80a0bb919ef025a1cdfd96765f6c967277e7862","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.4.3-next.8.tgz","fileCount":47,"unpackedSize":380827,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCBYD2xgoH0PtgHKSwxByu6c1BDwwNnDmmgh9odYRJIsAIgdZMS+C4iqOnT/9Og7kf47QebsEOgPeksyPcyvsz+RYY="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkA/y1ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoMow/+IBk3uF1IPWmCW++RV1uRm2IilyOXB/vdo23KjU63NOcIj7Lx\r\nF9TIACZTB770eWDW30jmGzU0kAh+SIWaX19E2ZbVqChBn7nkV8XMleiMSW6l\r\nEffBk1V5ROiGMa9xHNJ3pDpEVj/7yCMLFdvXDd9psZNo1HXkIVHF1Xa1yRd/\r\nHRS8c45OGpYw/S8jEdrg4L9PqvoYi4Bhtk4FmLUv44MJsDSBpMYoLd/Rce90\r\n1fAr4LqZ0+Xn5NlIsIJYX84+HciLngF/XQLOrEDNu+YOGRjvleJF+qyspInm\r\nYuI9Vwiax7kLhSEgIr7+geML/jqQO6IadatbQm53Kh3rC11QFES7mUwhf2Ak\r\nOL46yVlhJMc9GCYeaeRr6eAPHLous8rR9Qn2+FA3peGtTzh375TehYLovpgX\r\ngd5ZwuVK7BCMM9wA0x+lgYGN5ZDi0c8HdGP9QgNmDCVRWa/CVjqlPgo7LfZt\r\nV9xFSZ4E2CRmQD2lQ9DH9PDDv+49LhsZ1ELmVAoebbPBVdnCJoajZwxag9hN\r\nbW4HVjX5SVYNOYHSiuDxKzahijGX43RQNO1ufnGd3VE6SCJo1wQE5oTZZj9K\r\nT+icjwmlVYSqiN/D8/gjZT51s8v4M4ScltKootDzKtxB2YQKiOROGvkapv+v\r\nzaukDu1SOu0ugSfms82Q2T5pU030tqyZRGw=\r\n=9QL+\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.4.3-next.8_1677982901691_0.5306368384463911"},"_hasShrinkwrap":false},"0.4.3-next.10":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.4.3-next.10","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.4.3-next.10+f20f6a2","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"f20f6a2c0694513e9ce37fdc056e83a0dee4952b","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.4.3-next.10","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-511ZsayGqmG86fq19J2QUEILM7Uw+mhEtTzR03OBHQ5htNw49oxbWp8g8v4uyw0ZvfreEvu6pdkLVFORTp6JzQ==","shasum":"ff045b13b1818fd4e53a13ab14c12edd17a4ba15","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.4.3-next.10.tgz","fileCount":47,"unpackedSize":380829,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHFGPo8uliRbQXBhg98D2xZqplKfmTr6QrExzzntT2xHAiAWTPF2ZtpLGwoaMmP5siHP7DeL9IKvxlRiNL0OATZyZg=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkA/0JACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr+IQ/7BavvuxKn7CBR2YwTvukf743w/Z+/3OMwX9CkUr6Pe5W36UhZ\r\nthLXLFAD+eBkEnsxPYnBs7RxaEK+sVTqNJlfuZHwHSHwKnJXXILsFjsleWXq\r\nvilYSuLCNy7BN+BsUKxXYGs3g0bpo7DKku7Fsg/0avtOiBsEP8v65ZHuhOOP\r\nyN/TaIYXw1+oD8UZZfP3MUcmkJhBg4zmjLaRTCqEXuXp8I5qxWsdzjA9HJfk\r\nlIRSblmcoQiKxFwz3M8qiSPDZx/QHbNrNfn5xqAYTrhNU6xiXezt+D2zkiw6\r\nSqC6M1mKENEzU4Tr4A+fCx5hL6lRoHCg+ArCBHOim7lc2qL0fLt1THCVcuo6\r\nfeMVSmtdP/VVRC7vU+lZHdO57GR2rFDlEXndl49X3gQKVVKptwuf5/jMDb45\r\nHyvo5l6J0dFvf4sXDrRpMqYpurUucJjJOIL6Hgww0FUEhkiw7VM+EVZ+w6D+\r\nfPRl4B4ce20d2qq8byk2tKA/664JRbj7oQ7wgeu/z9scllvXMlJoQoDn3PHJ\r\n3y0k1aysbwMcGeh1z0go/JRIffqWX6Yp7K0ad9ZUyvTuxgbYtnkHBiLHL3J2\r\n2IrjPYTTNxHAI4sexA80enkAlObrjMb/U+k21mIXwSa3Ibvz1WsLOFyWulLz\r\nGICTZUOp9MCmzer0PEwWQeXnqTWgX75Ga/8=\r\n=m9Bj\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.4.3-next.10_1677982985187_0.6714427162741281"},"_hasShrinkwrap":false},"0.4.4-next.7":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.4.4-next.7","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.4.4-next.7+acbde02","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"acbde02ed87b8a6da36b9e6d467c3db9343954cf","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.4.4-next.7","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-O3HnrxBJ69MrK+oei8FwV1gzm3joDI9FfT7INkFeUpn4r2FTDxoHQmaGsHAjpRTDi1tBq9He5jAwv0xKdwbMEg==","shasum":"52f6f20ca7cc5db881a548265bcdd34fa9afb94b","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.4.4-next.7.tgz","fileCount":47,"unpackedSize":380827,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICtM4NbdXFxDgc6NH0qNT/Dg9EMfCZc68HiBCdz0xzNMAiEAyrQy8bFonOFye/a1+uDvs6U9AEyBbgLngIuODADlLpo="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkA/1eACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp44Q//c9qxWR9gj58CnB5/muh2gl9NT7BWKxqtKYK3EYypoSqGDI2Y\r\no0Q3/0Q+SBrT+CI/aCzkOUZy36upmyvUEHEKTTCQMbwMP6+Gcf5YUBhErEP4\r\nfh9U6okp8M5doNH6Jd8eAH6ystNVHrRo9qo81deVeMqj30Oasd2qMAorIcIP\r\naV3h41Qzyg0KGUoSThUy6hAurPaAZJVA5bD47zEKTrsufjwF1egA4HDrtA64\r\n8W6pX23V2bLSfgHXGqa43fUfAWFArnR6C89mYLp1XuU/asO5q40iudE30FJ+\r\nTfSyHuuKp2bxj/cMQma1+fjyNCVKq6L4v8L6yPGqSeSuLf5L4T6kcPzGBi5p\r\nzwYI9aHqDtfWIdmwp7pnbtxv6Exg0Xg6bwwkoyPx+U2637RCG7FLE+/JzbDE\r\n1Iaat4ySB6ecfd8jTT+QFQpgaS/9UDsRUZD/w24gR7XOSaHOOVhL1lxvYhrg\r\n1lsGz7WlPaddMSyxpuB3n0OsVKNXjsv/Ldsm4bdxWpFiAazSzHKgmX7LIiQ0\r\nDEe8rbm3O3y30ltw0LP1gWLb6BjuXipjCrUcjXMSdWOgOQO5k4zmassZsc8E\r\ndcvvDB3Wr/VkYouiZWDL+Ch3HJa4ZukYsWd/YrH0zGSGNCCLtFTGMO2DzkiX\r\nl6hdpYBLlqOggB2/ginEVQ7epJPcF+IFImY=\r\n=0g/c\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.4.4-next.7_1677983070667_0.8717283978982955"},"_hasShrinkwrap":false},"0.4.4":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.4.4","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.4.4","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"914505732070fa337d9b56d84ab8769d7bd0460a","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.4.4","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-FsKk2bXOp+2ZN2VdAaR7IrMoTYflBBkr1lYjagNsl5KjJyt9o5Qy/2oQP7VX9DXggAmGmyZMsHQrD2+fxpdVOQ==","shasum":"eb6a56bbadf2711fc3507654e391d5b6ed2de65e","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.4.4.tgz","fileCount":47,"unpackedSize":380797,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDyDC4cc7D/7rj/cnHLyJmbnJtu65CcQ+9ZCnh8LsLmZwIgSH3zw2KP9lF5IGYtR/JfMskWe+uR5XvX4+APS7Ob0wY="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkA/8gACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmoxJhAAig7k9BGDn2UvnI5bzhAMPqLfn6xfOLFMhGRiaRaVTO4KT98Q\r\nBuPFFGC1Ff1zw9wbPludF0Sa0YAADjEUtmZamqdUTZUliBnLwdEIuBGkbvAt\r\nAcEnA7/sJFucwmnG1BvLP8iRQcuKAsb0kUFgJVx1VSVgK+Z7310wiOB35L/v\r\n5rjWZzstfZC2wWb3FPcoIqNLHOUQ8734pUuQWTrG+WcZ3Qx2Hu3xipcem7uD\r\nHpZxmCb3AXLFdAtdnZS3FdiC4xGsuLuLJdzKAKk/LidMNq2QDGH17Z+YOBUI\r\n/yZm3jHKBTwGznQCvEZrIpxyiOkim4U4I1z3bDKoTSk2jmQkM/uMHqSDxb4S\r\nXzfOcxuTt21V45EuuyHujlteCpjvskclknjsEeR4bYAgiRyPQ5Ql2LjaUHE9\r\nuSUgaz8/w4CoNCSDgYpGoIt4e72ZkN9Y1Vk207CG+D3afRA60Q9yltIzNLGK\r\nmsavJJOHQM99qAicn0MBNibcQHc/makVugivBUjmDpmG0QjH2DII+8lm7GfT\r\nRLdDCIqmQzIB01eDvjqfpVUc/OSU8zj7pfLvjJzo8GG67J0852Foi+Yt3zv9\r\nXGMolN4QLwFWnT5p37spl2JKteixik2mrbm/RsAJDuESF/m8kxUZ/b6Jee26\r\nDyEgQVO6d1ebAVa6X5YvQOci1SBXYwYWL4U=\r\n=O5NR\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.4.4_1677983520054_0.23671201191554836"},"_hasShrinkwrap":false},"0.4.5-next.1":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.4.5-next.1","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.4.5-next.1+3a54f22","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"3a54f2256e265a957f0be94b8ce7b60718cf3f60","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.4.5-next.1","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-sYtcy2bgux5HDxlH2NxTNu+ZSZ23ScE4QTF3IcQmV3Ondato6SgaQaQ0hSdamUqsJoCfwYXm2P+jpfHFLNcriw==","shasum":"313b3d247cd78c1ba10f144d4df5bfd9c70df476","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.4.5-next.1.tgz","fileCount":47,"unpackedSize":382145,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDhQyJkQn7+sh/dIVjVmrNddY3fPKs8Zl2130dS6r0v0wIhANGKAyjxw2zHP34NpCAvmT15yewrM21tsctpD8l59fry"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkBSXoACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo80g/+Mcbm+ncYB5xXQOnRT1n0U4+tkF3724eYQKCmAH4kDBUYadBz\r\nb+A4Vp7G43J74kErJDDf6Xd5BTlm78wLl37mLf4NSWKWLsl5ic2PD7OLyRcL\r\n/etMT45rDjRpnTrKH46SRx+6LExQWPyTaBmTWaf55Qj0cdlRm1C7+LzItnVu\r\np6uyt4T9q7Lp63hhWPpyotHk8nA0s05oZBd4lxTu6Ut7PAly4O0rRJa8TPX4\r\ndOOzRpOgPA3jT3x20G01KEY5X35XS4eQUxT3/NuIcR27C+VjZ1HU1WGlED5T\r\nYQmw9ocnBlpFT5jv4UPcuGLNrJ38XZDtg0sCOAokbkvxTj1D/8ji+ei5XdZT\r\n7wmCfQpjNE+xRAbq49M+iYx9ss1Oj/fTkisEvPBonUuZpmZIxKBE0o9P97RR\r\na3l/i4Ll7vofqv2lMoEc/fwiznXTtnZPSlIrQNQ6sP7azi4oM+vv7/008k3+\r\ny9f57McS9qSigt1Tb5zgsRrc3ReyIlGeza3wA0qqi+kJjbkSkz7DWgBFLSxK\r\nqWfGykO27OppMvF5guPxf+uVaVzCHZyonITEt+iBsDqQrdIajgs5GeoAaVL3\r\nBmB1Dllqv6qdf+zBCJhBQIKrztokpsu/axTdt1CYfNF+1k3JHYYeaxOtkmNp\r\nDcY/u7lMKAZalMpkrLyYtfOUa1O86PBJZO8=\r\n=LftQ\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.4.5-next.1_1678058984379_0.7984786058370006"},"_hasShrinkwrap":false},"0.5.0":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.5.0","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.5.0","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"01e097270040b1bdd686cc6e22ab6550f606eff4","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.5.0","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-jbfC+zJ6ULVhV1caCfykuz3md5Cg1QwkKsJPAEycjvI1W9DSc3skEvhPXo8JZxOIGNnkbQlcAACFa0a5YWK9CA==","shasum":"cd279be4bae09e2fba6ebd10db78527e31747152","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.5.0.tgz","fileCount":47,"unpackedSize":382115,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIEzk36YMbqV+hxTC/a8m5ikVd6Wj8/M5lYEamDUVd69kAiAdC2M7aQdTNKaJqEVWldTTFq/+WwW4PllFWsNJtWy3zg=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkBSgiACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmr5dBAAmbNl2f7PClnAlNYLiqVsFNu/nwm4RK3vUfAmmjlZyQMsB4Ag\r\nEM05v+nd507AYlji1Ia9wUr9Nn4MsCvJ1P+/a40ZdRwkPNaaI8Jir0iCtK80\r\nV5b/jt38OjwWunQGxiBJ46iqBYLUWMCHxVTolEFFyAhCZvRSUUTJLsLOIbhF\r\nARSd3iU3LgRPKe+qQNBBLj38rTVUnAvKTsfDtrjY4rE2X77VqbUL6pfDlpS+\r\nT0j+vHUUiHjiICQw+gCv344pFVhhdb+lMBDLmMF8WakbNnJcAPmhuDM0fUjH\r\n/vYFjIqV54CF8k0B/z9w4TKBdlbsGswmrPOgNn3nfTHv/LxA6x+rNkChlThR\r\no2hQnyANJDdamELURV8I9lPTw/RpcAn8DOIPxntLWadFcnnxPTuVH4W3BIts\r\n+iC1zUwjBfZFTFdUOygYaQjMR8Ig83IFcAGBLtkDV+QEeVaCPghzAIO1Gg1d\r\nicYe7ggUBCmRw0PUjLB+uP5FuSqjL1lerDA9UirqfVgf2KHdEbPu2e39udL6\r\n9B9bZIkou3/sTihjQAzWCSgN0Nhoo0yTID4fjUkYHe9YUAbhi4iAGIdBIAGT\r\nN9vJdvs7EFDAnzrrT670dgK4B8WNVYndNEtdCuDcVdxLCrTJfjdNe2DrDywW\r\nACTUMPhaPwZK1xvzwEYw8W7E9orboxxZyWs=\r\n=zZIM\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.5.0_1678059554283_0.9579427043127526"},"_hasShrinkwrap":false},"0.5.1-next.2":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.5.1-next.2","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.5.1-next.2+1318c70","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"1318c70da3b2bcf211ff516176c9fa47865b9d62","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.5.1-next.2","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-Cdho8o+wG/aPDa+me51YL7s5/wJtQ4VXT0gG8MhmD9q+Vow5jv7+CNwlkn/0KoJX0FZ1nbqKKbKuXP+vuoLj6A==","shasum":"06dc1f5052f07308a7679dfcdccf5db762a4d3d5","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.5.1-next.2.tgz","fileCount":47,"unpackedSize":384260,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDs0AXALvCCnExeo+nX6X3G0jrGUIv7R2zJks6yQCvvJgIgYhzxnBPsdbIY27Gsx+HZqA8a7UNtbGRH0rN6wQTQJrE="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkBbcaACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqNDA//SxJR0adMCnRQ+MncnpZUYf3BQjK7nwjHmysZcMj5iaR+2Dn+\r\nXamtgcbxbacEMBrxVLTNBIGN4NzidNL6/D7D+MDfCf+nfF2sq0eulc9sq+jL\r\ndwITIgZ65LKV3utGXqk6+zgJ8QPOqwZ2Fbl9bGAo4CN1CtcZ/KnKvoVOtS6j\r\nBonPfJzrs407N5uukkl1YltDfmUWjZQ4b+YcV7lwQ1x9JPXuKaR00Jls3/Pl\r\nkAMt1E4bxKkJ+M/yBEJFNlbFc24rCSQNndlqw3sByfbwh4csCE1+aKm5o6kg\r\nJTrn9PiJCtJQw6tqDRCrWSihYOrOpN48E9vXHngyD5F0p+tMsOvXwChAI9y4\r\nDe6YjlFf0gD5j+Yut+I1gj17nTAqIyrYL0F5yEAquo3WsI5Pj6brm6F1Myk5\r\nkzasTL75kQ6utyLy3s9bXnAYPZy25IBW0HhMUWo3n+oiChXaQDCB3lE0rxE7\r\n4GLrHKJygLeaXLowgwEno4lRKXFjGRBaFsAqo31qMxer379mkKQLqWYhWDbb\r\nR/oZLxmdy8eLtv/CNuskHQ4TeYeOCurxMwyxCWHc+USYoz/VQak/6a9oUp3U\r\ncHA2bycN3ZkU2gYNXoeC7/i68rtjNtLjRojLLkIQZcTabHfxv7DEOgRgj2vH\r\nOybZceskRYKoWgR4Yel23MgYu1gniZ+8JK8=\r\n=neYC\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.5.1-next.2_1678096154405_0.08807278280198694"},"_hasShrinkwrap":false},"0.5.1-next.3":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.5.1-next.3","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.5.1-next.3+4b3aab7","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"4b3aab78027e4cc2fc211d88e2b7cdad324edc59","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.5.1-next.3","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-vFZKXjY+XDaDUNUR2N+cG4V3eidFPosbxw6teeeMEUuZKAItfx52kR9DPklwZnuCnVpadi1j5A2dpi0f6rvP2A==","shasum":"63d8947a2cf1a3efb51dbbb42e9e7487a0c993a2","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.5.1-next.3.tgz","fileCount":47,"unpackedSize":384260,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDxF+zFKifotKN1OZ8yIXmD+AogRPLvaOEmRPTqkZfzAwIgZ6o/yszJJYz0PT1QrqUTeqZHxHUlj7Vu0q1LqEO7x3w="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkBbrRACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmppZw//RfXMlMoqpw2acNBmVaBX5ZPYqv2Vwtq1U7202huA9frvZkrz\r\n1BBNUPrLsZR+BCRh3M7dlsBzxVnKSCN16lSRgkJ2hayiDW5hgoMVi5/h9U1f\r\nQmkG2P6W6k/gOJJ80Q+iv2jbeKPAvp9abCY3tFvhth5V0HU6VucIDEQb2kIU\r\nePVbkzguyMvQLhWpVVe98BR7+BCnWGFqGmR3GvaV5c47Z9x1xY4VtP07POk1\r\n7aaxogLUHyz1B5rMOy8U9iJDv4SlPnxIcDfUDVDew3k0n4XzEneuG0sn2z4G\r\nkqkrbL9tZeaIHDtlQHLCrVvXssEDhFDR9o9dc9Nlz6aU/1Utv/7JibwZT9ws\r\nNXMScz/zkzbRUIZV5Bi8EjHUep2mbmMdhvLUOHqzAFhGZBKbfj11UzK2+DmQ\r\n6P7mK951SyOiR2AFm6PS2ofOvcLYEEh9xB31/rDcF1KPsmfIrE3h/5Bd20Ae\r\nv3KHYkMV95jXzcMT5lV8bxj0F3YLYo+q+YONnz6P5WEShT8UXINjoEI1i+Pl\r\npgR0pc/T/GT5El6+bhBB0925FznhI7xLGlzJlWRK+gxAOMZXVr3YgMY+NyXh\r\naPGjisHXCMqVfG4iLOxF0UHBIZdwb3iuoeBpTuNxowXRieEh2M+JZcX2eJMQ\r\ndSHC4k7VY5+PE0L4rtRq4wv0J0YMVbEqwG0=\r\n=Jgh8\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.5.1-next.3_1678097105057_0.8487816026465771"},"_hasShrinkwrap":false},"0.5.1-next.4":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.5.1-next.4","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.5.1-next.4+35caf11","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"35caf11d5ace855e3e20ac2ca7860f13e71b197b","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.5.1-next.4","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-tatR4OQpT/VNyc07ppXwblX9jgKVNIKDDYqDSMp974X5aKWLbQ2VY70l4PCznExpDg7pfStjgYop7ZybcXFVsQ==","shasum":"5875ebc91008bec12d371a9160f3cd6c385fc24c","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.5.1-next.4.tgz","fileCount":47,"unpackedSize":384260,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDMFCCs0NWJsbq9DCEtrrTH/31tBFsqHqjcKyPzvq7c0AiEAxrzEhHJbXup5Zs0V6kU6x9hPKncN8j++IF9qaDXSkog="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkBbz9ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo5xw//VGaGVp0Yg7nxUZvz5Wv4dEaT6AIpLw4n/LjEeFhtSbGRkmtL\r\nRn+S9ayVMvsppxu0okO4je7Eg8S5GmlqQhD17I7imHaFC3BBb6R2MeMvtGUQ\r\nLX0FVRQ5XYj73qulntYRYQTXlnJaM3wjo1j2HHm376BhnU5EH1qpic/I3ARt\r\nsO/CtOEUo0ApiAW4QWoKoLUJPUUPVrAOpsyQDoq9trEEdH3Xskply4TzSTJ2\r\nr5FMmK/eWakUjRc6re/A8rPFLn6JsP2jjbqZ0S4m4nVwbGx3ooaqJBLZOrPW\r\nETzTECJ6BTRZibynLHNbAnriy71fyu/GwKq7jy/WL1ZarpMmEUMcFWK9hdX6\r\n+dfR/3x5/lyAlPDo6xt8owVWHqOf/qlkNjTzJBfu3eH8DuvtHl4Fx3EU0NfT\r\n72nyV8Spi9eG8jdkShP8irFh0fIMzrA/pBZHOM5/9WfX3eXNfTVVjNNiI2TJ\r\nddOABl8uGnZ043bRJkYRevSpxJq8x6jQsx0vsX07rcAZLTfsJkRcIp3JXrTv\r\n+Dr8CtwJpe8niODiIe+erw/g+G7y/V7zvXhzfRlw7abaBw40a7rW0kMaST5e\r\ntodQUexMPtNaDNnwDLuLIBPPvjFrD1LhXyKyM5qVXy90rQSollqeBEdbPbbM\r\nA9ypaduThVr/gma+inSfYKUFEDniL7eCwa4=\r\n=dUwe\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.5.1-next.4_1678097661429_0.12853456789510487"},"_hasShrinkwrap":false},"0.5.1-next.5":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.5.1-next.5","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.5.1-next.5+ed971e8","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"ed971e89e60176984363315b15f6b18fc85f5061","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.5.1-next.5","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-M/xqNyfRFkPn1WrhKEuA01zTFcaVrZ7x7Dlya3odjxAf35DozlaDbdYrAEovYn5ilaW1KJvnTujPkfIubp36Ig==","shasum":"d1423b9bc59ef1d07f170187efdf26691405ba86","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.5.1-next.5.tgz","fileCount":47,"unpackedSize":384260,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIEzfIQcBsYt9IxoSQ9Q3ASABXQGboODo8TZ4UIs/Yo9FAiEA1cZu3ZJ9UsQLS5eab3FOS4Wqro6w+23cq4D/A4WFMAI="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkBb6+ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqUnQ//R8FWzuhaTlPxiQOQ0vCeJEvspDVQlcW/RSFVKqc+WulHjrL7\r\nUeCqJjqSIHvfZyyJkg++8VtMJYn1ENiLzt2fFWdW4OUNW/Sl7zYR5niiLb7k\r\nJEmhh6gxubmj7gyIvfguaoiLRR9Kf5E6fvthKJL+BqP5BBuQmQV8rHJN+BKV\r\nXn3OJ39ILGT5GuCyVyNz7xdttNuzGKaoyGOZyyUcJmZDnRrtRuchzAUP+9ft\r\nclwx1f+ZjEWV8uXWZtA+wWi0R4Rbwxf06+aiZ8zryke9CsH+/Q8/arL4YVe4\r\nVtX21jK008jjOmyntJM54Vmm8orKP9QFwyJESgIsyhlNu582ook3ePpSTGyY\r\nKrrGBCXfnRIRK9uzDHfrDIvjNdcLy6knIO41eYaGthcZIc99vVAIkR5pjn5y\r\n12oVejOrqdTCaAZMroaBrlhv5KCDMIuSjMKPWDfh9VyOvIMBIRHOgETyqKj5\r\nw9yxZCHYYYH6nEhTgb5rQWCOWqMJtkmsLXa+BkgAlsaQlI8R4P7wQ74Lqwzh\r\nwp1TuH4TsP4sw0OpHJhTqBCrI3AzwWCmM7k0Xd1Ug+QZ8FtCKacx9CkLKsLO\r\nH++jMr3rwcYOko2yJuLvlZurB0++7C/TXt/ixtYPmX3RzelKDYaGEiBIIsqN\r\nwrg47huvYuPKDKYc7jnw3hMbVFDHJWrDeZg=\r\n=PVRz\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.5.1-next.5_1678098110313_0.8153707109701429"},"_hasShrinkwrap":false},"0.5.1-unstable.1":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.5.1-unstable.1","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.5.1-unstable.1+27308ee","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"27308ee6d51241aac71bdca829db0cd8a3b88fa8","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.5.1-unstable.1","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-5T6ZwoKa5oXn2VBk5snnmDyWRwu3Rk6MZeVBUs3uPbZXwXAMe9CsitfFYJicoeRtfB1drILZKAOBwVsswchS1A==","shasum":"8882531a4d8a1c228feedcf3fcb92b975de419f1","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.5.1-unstable.1.tgz","fileCount":47,"unpackedSize":383490,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGjQn0ZHgUvtKWkQ09IK8GoI7gtxJbUGregaoQC/4Q3OAiEA88DohE0igDzT7gICm1+1PMR8w4IJgt4SihKcCtbmQvU="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkBdrjACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpS3BAAleSpMHVdCz59Hiz4ov7sfgTc/PlKe+bJ0aqrbmcUzsiwWJ0R\r\nXGgE9C+tJYM0LZmfioDqhgFM2tcg3E+ds6pQO46nB0NxGjvcwVpN4tiyZ7/t\r\n6x0jVHSlTn00VavMMbA+RfIavvMhiZv+FXHI+MZx8WPahaO+AJuChicF8V2E\r\nWGK2lubrX6TWCFjYHoKJhYmxbGB//P/bv5zyAsWGxBm0s0Tye1xGrprPeD7+\r\nozJrulSYlEsUjMy0r1vAuXKnnnhFb7iCqBjeC4IGmdayz+IY4kPBQsXmL9+L\r\nX9vre0ZIadLuJtwBX3deLEKt24d2P62mRuvzTDnvjv11rGEvTPy9qJaEQbls\r\neGWPMaQtr277BS8tcs5L2B5urMUmGALdGyKaG3o7AAqk+AaKoVSrz9dnX9xQ\r\nB+EZVAiv9EDEb7UjQq1tNEhRVBGutWS4i1mXIwHSWyK+rRw+8U2chQuxvwak\r\njyweeq1DaItQrIhLZo9knCL2w3P0wl21qwMYfODNl2u30a+M/Ab1a4y3idWU\r\nrJdR7DgD3rhfe5lKRClWLNvYEk0CEFhiqLFRbfNJRacGilI7Y7pLynrxq/lH\r\n6cAjxWlXx7PW9YoxuvzwyoVizMoCDsoRpzCveYLGwxXG/48YoNRYDzkFv1UU\r\nD+3E0J94a6mztSRI5AHFmiVHPZechHFjHIg=\r\n=YqfZ\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.5.1-unstable.1_1678105315202_0.7351376297459453"},"_hasShrinkwrap":false},"0.5.1-unstable.2":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.5.1-unstable.2","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.5.1-unstable.2+a87e8f9","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"a87e8f9d3095f0f8408e07bfc2aa4dda30ce85ae","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.5.1-unstable.2","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-E/2SyoZNd6FSlQNF1sPAvjL3bkWhljYxvat3AuP+5khmGFZoa9ZHJe16bjpx1jjmVCxtM3OKhfRusxTpd6JNmQ==","shasum":"89cad726eba9f8a7bbd544af388a512932cfdaec","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.5.1-unstable.2.tgz","fileCount":47,"unpackedSize":383490,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDegGh3zAc+Si98AiXCSALIlfOBxnjsE2heRDBRdubAjQIhAK+dAqye0gUWf3RIEIC0eL0UsSzyz++6hpGipP5GV+9G"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkBd84ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpAkQ//bcjNyATjTX1k2Kt1yzZcHOIDZpLmGL9czkounK/7f9JrKCYC\r\ni5fb2NvP1l0hH9dhzFOTmYLHrVERNIQCdWcMEnSD+Wt/sRnwg+UzuYpsU9Bb\r\n1xdv7vZ3WQH5oNJSWnQlEfZbjU7S0waT1WPy31iqZbMaVjSMDMf2RPcnUSLW\r\nbRGse7Yst/qUwn+FPl1zQGumEkAjwoaDifW6aRD2YU9LOUHIAuOCNPUhWULw\r\nNdKN+I4dSH92qvCnGgED6+KwBM9RozzxnVZAc8E+OPEuzb1Pdqb9K+7CazyJ\r\ny+2nprYP2okpvqdL4OecFgRp21E/xIw8m7ocigEwjXetptymMTJNEhugXDgb\r\nj6nOhIsPUntMtpkOHXnrvlePi11kcvFkCsjjMcWjTQukLsnjq8mUpKpxqekf\r\n1rSG5I0V4VhtYg7E14yXE8frNhfjLbJW++o1ALyApxLaIeDEhGWeDWgJcfaO\r\nAs05QmIEOEK4wpmSYM4Sl42DSC78JHmgVSBEIyqYo1b4Goqtte24C0BQcgxH\r\nOsMlYQ9mGlxb+zg4sHVPeCdFH3AYwFUpTbxNd2Yo2p0yqEryKeHR6rBisFyp\r\nI75eny17h+TVtyKEk0NK/+f9z6txlqhGnvbc3gOfi3ojcN3r84ExywZT6lyD\r\n622GDfjKqismxEqW3w4Mce3clKT1su0MgrY=\r\n=jp1b\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.5.1-unstable.2_1678106424388_0.9335838034831219"},"_hasShrinkwrap":false},"0.5.1-unstable.3":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.5.1-unstable.3","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.5.1-unstable.3+ce366c6","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"ce366c66fdd5d80f94835d169c63ead2519238f4","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.5.1-unstable.3","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-ItsEz3rtdsQrtRm5LLOOt6U2b025ASNotc0FoGpis5PF1xEBloIIVe8ye2lNMzkZsK/MtIIBzGg0rY93Y0pzrg==","shasum":"9f8572e9d746d41c6c27b2a4d297bfe043fce3a9","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.5.1-unstable.3.tgz","fileCount":47,"unpackedSize":383780,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIA3AFzvIZEZx3C4W3rucIDi2rvziUR+OmQjn/bRP5PwTAiAvNGgGS8BWO+16LhmsC5u0ha/w78PyxyM0XCoDi1WQ4w=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkBfO5ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpaVA//WwRskw4ZGiyDUnQP3mf5ypZ4NA8TEuYrOy9jqOytx7gEJ3UG\r\nM7ePXJ8RyaCShGHRNs0GFH1Oe22keryB475B0leogO/O3JsOC+i2P1+73z/N\r\nG1C7qNpcB1O32smF4BqGCBjiQqZHT7bxVt8co6x8TfW0WPd4SpRUndGEgGN/\r\n9amIndfuL0Hr9nZa/uSLHDR4GOCtf2C1WLJDhTLq3qVjYn/T2iznTQ3Fcgr/\r\n31wV4x+OI30CC25dg0ydh9UKPVQ4JZBC7LOfSKj5VjmoTv0PIUFJF+JBPsv0\r\nctEf95nUfBpoF/7jMEg5n9bHSXKaNjiYc26SaYJ6As2KmWr8OhI802H01gnK\r\nvyGIDhZryIa/oFZjXGENJI9IFwQKU6p0V78hEck3VZ9QiqZhXr4UDNJydoZD\r\nKf3AwPYLTXmiHFrC4aLN5hFR/W86h6O/bo6u+gJk09it9kVqvIGUA65SVSlh\r\naESckusWjK0lM5O+GlKsnnjTghDc49iduhzNoOVDqOmPCslxO29d/SkkgOM4\r\nppJzLTthQKQNpS67GUd5so/XymvDXC2vI6oQ7o4+K57COiidz2c14yQuTpFK\r\nLxT2hxsTGB5WsdC6oCKDEZNr5Em9W4hNC7yAcWxHAQc5ABELyMX5f+FHmaTz\r\nCimBA4ifgE9MrJXLLaFbMjGVk+tElzz8ibg=\r\n=cF1W\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.5.1-unstable.3_1678111673712_0.1628658124096498"},"_hasShrinkwrap":false},"0.5.1-unstable.4":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.5.1-unstable.4","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.5.1-unstable.4+da271b4","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"da271b4640accf7781e81fbf5900bb0601d0dc60","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\nFor onboarding the service in the **gx compliance**:\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.5.1-unstable.4","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-wb1938B12J/34LbbMw9z6ooxys3w+sZeT3Wdbx0JqeRrFzY/5rzH6dXDUuNirptYfL/DRzKgHQwT61UAIj4xPQ==","shasum":"a528fd1dee2159cacc897510af22d9351b7699a9","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.5.1-unstable.4.tgz","fileCount":47,"unpackedSize":385265,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCSNj5jSkQennE3iRQLZh7fVSonjJONCwJ+Xj1W5BhqNAIgWzyqtYJpby3pk1boSLtFdj1Sf9zONhCuO+ym2gv4Aoo="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkBfuiACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrzJxAAjs3uOLXfpy1UKkMXVftgpYZXjPxcGRS7gpC6Y5sEejyBhbn7\r\nWR2AIQBncdcEfRe0jYakUo3cJZtigZKrA0OVF3I5Gujgf9KFic02Bupk5irN\r\n4OzwWbIdsgHWVXcUr0+lEKWYU33VqrlguRI9PrLbQqlQ0jQv/cVmCWx5eUXL\r\nFwgMDzHbZgeUiNWEFOx8NGCFkm1XCk+nXhgxDfofYj3LUlkhLcVewOwcQiC5\r\nV1arEzWv/pWJ1kU1+XpwspPg1qHWtSjKTwWyvdtPR6ZY8GZvKxkQeohAA4EY\r\nA0mTLyujmFatKUW1ZfzrP2oJGKdDSyEF6a6b74jG9bEf3IxYvawVqy7EuVqT\r\nWhrUPBvJbVwfmc9DcBD3FQzExuJqfVPB0dqdqNzQaVygzpEnZTtkaWm/vWSB\r\nX57UoJkMm2eXjsKQmRnUYLlfI0mPQVprf/IRJQvoiYDqZdca3J0cyBmWgskr\r\nkoZnvs+47SGOoesZG7JVw0K7xZwoJZ95tYSssBQo6Bll+s+j1Zl7Ld4RuDcd\r\nfHD/km4Z61sU7iB0BrCPVXzAbxvgvw9eHxz8bWGupJHI8pf1yRVXdeRXJFD/\r\nhy9fgDpnqpfR9AAWxqqJldPTIuQ6slEG0xkI3G5d6tTw/h4HHjcj/L7N09uZ\r\n3bxEFlw1zdCcJmgO4HKa66mNsBd+0GD2y+4=\r\n=+0aY\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.5.1-unstable.4_1678113697991_0.5427076240845441"},"_hasShrinkwrap":false},"0.5.1-unstable.6":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.5.1-unstable.6","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.5.1-unstable.6+047b36a","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"047b36a6f121ae36aafeead686b570f8f0dcf1fe","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\nFor onboarding the service in the **gx compliance**:\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.5.1-unstable.6","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-6u1gVonQWVkhIOflUebHEaMPnsFLeJlC6QPhKnkI+FMIVEN4zsm90YypUn0nGuSRtTnCg1vAeYPZROuwef9Uww==","shasum":"20556e54a4a64b324649840131ccc11e84e12d21","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.5.1-unstable.6.tgz","fileCount":47,"unpackedSize":385249,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGhzrZ22SiuGEDGCInjeXnxmwqov3CpBDPFsUXAj9TBzAiEA/6yaSNKimmj68kgbXwaVwKBEvB8j1ZV9UPUcLoOQEe8="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkBxXtACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmrn5w/7BjAploCeK7r0Te0clgS1eNQT4737fwCuiTKB8QxWU38TAQ1V\r\n8ivwaofMOdnuSNvZtF5r7A7E6UGV4tJ2wwcDZyihMntwiqQYG5Gdo+fEjwJf\r\nhVJN45WU5teixzdpPf6/5R4lP+8aURr8UGPs3NlCmWaPCmcyxvYYwje3QxXp\r\nbvLrBiAYEX3mpCwE/FHDRuc0gF0bwnDWXAIbm+pQhk+lkIx2zdc+DciPh/1G\r\n21PaTrKNAhOXCwgoKfpiIQpJXlS72/z9KcAHClov4Sc1+9NP9guKF1VlIlRT\r\n0uiFLQpXvqSta4EFQvZ+DwJYZH/VejapWkjXcD7BHcc53JrWnvfSV/TcN5S4\r\nkkUL0m+DSk+r+W0FRSR0sLT8Vh6rC7Soe/yt7WPXA1ad1myxi65FoCtB4BH8\r\n/iMNIP5sq6zCUEfzZgQZc7KHAPCDqI1sW7TNwcka+Mp/UpKEvNWyp7F+Qt/Q\r\nl1kv2oTzC2d7uXXH4no7WLumFayQhcOCxOSjg+qAtJzKlYB4SBgaUZPsCp2D\r\nTPaJF6HvvKyAKAPof6Kr7rBeuMNsrJgETgrjJTkp/vHbbLG0r97oc1zNyAHs\r\n2o+ks1qVNg4ixXJEfpklr6b0Y2d92/FtR/BgOCZo4qfrJjxk6fxRT8JXJ6VL\r\niKePRPn5AWe/HjH9ATkegA1fbsfdJZBrnFo=\r\n=XS4E\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.5.1-unstable.6_1678185965112_0.6275087464233993"},"_hasShrinkwrap":false},"0.5.1-next.12":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.5.1-next.12","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.5.1-next.12+ad98414","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"ad984143ff9fde9d36918eb9b0c19169bfa60d46","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\nFor onboarding the service in the **gx compliance**:\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.5.1-next.12","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-QG8ILYWisQEwcOtGWFiIgv9/Mba3yDqwCe17sjyXdpszlZhoITd1NjvfRaSDC4HpuL3K1oV7I2vwTJZhHsMsBg==","shasum":"ab703ca60c080f5aded771afe8227d8e0ca0c05d","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.5.1-next.12.tgz","fileCount":47,"unpackedSize":387358,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIGJ4rFuSv43+rCPcSGwjpakwOVPKz9vfblmBdmye6hYnAiBW4vMjA5Taf+3KW+vGRPbRT+pqzE3SUhmlcFklib1soQ=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkBzKmACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqJaxAAnB5LgHCUqtDh+4+8jK1TQ7MghHF4YqobINWrv56klXGw5Ogg\r\nQ3JzyUCcIpH43PADLJt03PQCi56ew4hium1/9tVSrD+FcIz16qq0kXdokdVX\r\nVq/5lCPVcJx/aw8GoMRgBO5WhSq3t0h5Ob7IIkEU3dZSxdZNJtjdZZ9yxbJC\r\nwOnW0JcG2quz4uMqkIKJqBRjAV85Mnc9cmJKNLNhbf5SSph2wvoiKxdBlCeo\r\nkr6Gbz7lAmn7rtDAvDTPcm42rPAzD3oLsWVdN81EXjoU3ekSLINFt8WW/zCy\r\nVWPej7nBcS/heOExfLcCFjIG5C4oqjoLcq03OUzKLaxb3w+V7J83d0SRsx25\r\nd2kiYcpXFv3uIPZ/QxgEN10qLFM9xJaOTZCzItsBzJ062pzD5HIh5+rqtzFl\r\n8nZ18Gw664dplFF9pwNcA7MyUGEEcYIJ4OF+feQ2MobT0kJ18A1fAZHlhFPC\r\nTsa5iyqo/OWgVVkfvJT/i24qCigco3vr8s+r60yJsxycdiyGTpzjVjijR6h4\r\nLTECcMHAKFboixAYejLI1XR8u0Enaz3/opyDqVTQjwLLxVD2mG+Y7xEUpjJk\r\nAOwbBd7IOM2MWO1hkfAeSri+mT0f3PF5Jd0CErrsdpJM/xf4Be3ZcDg8Wlwq\r\nVri4pA1u6j46YRPn+VW6GFgcyYFTqiJIFbg=\r\n=1c1/\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.5.1-next.12_1678193318035_0.8415533821876895"},"_hasShrinkwrap":false},"0.6.0":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.6.0","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.6.0","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"e08d916a45ca7a3dd81cd62556004157cb98f6fb","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.6.0","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-mtFuiViVRpCVijkUhJOaHIpBtzSUmfYLErX/m9NDCn/VpLMIQmSzPyejQG+H024ss9fbK3TT0J4QozFo1NNKLA==","shasum":"dffd0ec938187b13eb140f83f3cfad0796de5d39","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.6.0.tgz","fileCount":47,"unpackedSize":387326,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIAkE7n3SxFoInpys8OFB/Q9mK0jXZGRV87Waw7/0KOBhAiEAktBQrzGj3LXfKaMZcqXUGDbc53p0cMBrTvBxWAl7cCs="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkBzUrACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmqw4Q//d3EaTFEyiXES6WktFp4qrq2llk+dIIhhQq27ncWX55N75kbt\r\nmx1Z8P7Cfv6RCBG4s+b1MpQ7sorsUROGkI6sOkCck+ekfJBmkRN3c8LJPQkF\r\npQUuX1Uwg9HOuKb/ov4he56Dg07WQ9a49244NlUpPXC7W5p7VqYdF5GAKEbq\r\nCgdHNomMd4yvOR3/J7MahRTS+mMpNQB6vZ4LSoZIO1oTg4lWb+RybhTApeM0\r\nN2lMfMG5xYBZSwycNPIbQQxj0lV+cAsgb73JKc4zUd5x/KS3ZbH6BJQIlbUb\r\nQLQvZSoWEpeuiF+mqZJqwA0/JURWY+YjnttC59QdcmWvqzuS/Ir6JTv9uIfx\r\njRs9CzXHWTjVsi9kiPs75UNB37s82zBV4U7AfTHR2f4EJN+JIRxIJE2YYPZi\r\nr9y05vup1bBo3j20hFwd7s5SYMO/QBt+R3LdmI/ZzaFu9P+8DOM0O2Tpv9kZ\r\nHCq6vSD8jeIQF9L0ISLKuTxBkg6ZUZjDlXrmhQsXPvm4CMbOZ0/pJ+ajeBxL\r\nEIt3XDcjwDHhEU9Gbj3PRyucj8k/WMb5gKGJEMvAl1Yc2H2l6uQ8Gc5P38m/\r\nbvLkXUDPIxtf7jlKtzA36sz+wsfdthrA0PkQYrAkJ4VR639ritOpzRwlhFQL\r\nWXWj+beMXNqplc3eVkgp1GdTGA9dmFips0A=\r\n=ht6I\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.6.0_1678193963768_0.8760693874828598"},"_hasShrinkwrap":false},"0.6.1-unstable.1":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.6.1-unstable.1","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.6.1-unstable.1+77ee419","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"77ee4197247c478a6054aa80640f119900b07add","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\nFor onboarding the service in the **gx compliance**:\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.6.1-unstable.1","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-gJOA/xnZiiZ2g+ouuZ2rGlq2q6wUleeqC3gdK1fpuCsapCtS8rLt7Kbq1pGhzCAHQSqqR3P3mZGw0y+xzKb4Vw==","shasum":"40fc9080cba923203e3d1336c632fbb32ddb09d9","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.6.1-unstable.1.tgz","fileCount":47,"unpackedSize":393219,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIC4ePlbniT0KJRWfnsxIx0dVCNcV35EVWu25WasycZyWAiAIfaYrKjD53733Exeo68qQOkKrdGUdsYLxjfZf8oG05w=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkCcq0ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmq3Hg//euYNFyM7fVfLOiVGfnOziuf0/cV4bsn6gaMz7m8Pa/amahhM\r\n2EAkarkGv1QBC/FeKffhxhlXr1pOds0g00XeshVTzUMHUTtJx9GQLtbcwckj\r\nuCaEvwY1FumR6bvscMHn1u6A1p0xEGfD95u2UetrXnxobzktvmWQfrviZAwd\r\novRvfm2MatgMoRsvAePIl/IXKxG6IPwZDu5b5eYFGht6ACuq+OhhHdLVkD0R\r\nm6iFq6pncNNYvl9H/eZ/dwnVJv989xDdPkLfPF+rfOETFNFwCtnVXDxA/ahY\r\nQ+yWbye5Qv9ZlmqrqENTJwTOAhykhStMI50DApF35ukw+bMlr8LcjRFfDoMw\r\nHvtDx+XFNH5VwyU0qK+gyw06+2V0i3dwwIRKcu3TdzCzRvYyNZ1pnNkAsBFy\r\nutFncsJom89tk/Dk/ZyDhSd0d00NgwqWj/rf6o8m90INiPCXP5p5cTQXXkFH\r\ns6rK6ayXZecIh+VH7y38qXB03DCi+EGudx6tprXeewMvggCEmtgP8gSq3EWU\r\neAUpdH+7ejdCcQGGeGyDmFMes1zRduhKvWmeD2j/4U6HiCeMiw50wvqIQEBM\r\nsWy5w8rAILa60pFjuYRElRs7QA2ohLEw7i+ZUKONE6iZ80NgbaOhqvX8rq4e\r\n/bfXU+m3JVoK0vaPPk63rlg7gCFf1kVcjvc=\r\n=6lTo\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.6.1-unstable.1_1678363315876_0.2642216274693989"},"_hasShrinkwrap":false},"0.6.1-unstable.3":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.6.1-unstable.3","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.6.1-unstable.3+5ba9862","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"5ba98625ad4a27463884fa00685fa2d39b9d5af9","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\nFor onboarding the service in the **gx compliance**:\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.6.1-unstable.3","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-kDHWaaN+7zVITG6dgapY6QKP9YUG5O/Kj4A8QUtp4zgIbn/SxV79cNMVJ3xdfNJCZk4ZCumiOgI8WrfAMToJ7g==","shasum":"860c9ddd8120f882359dd9dbc0c1290753b5d00e","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.6.1-unstable.3.tgz","fileCount":47,"unpackedSize":390770,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDlhPzar2c+nMI1jrEpVU+gbLXPGq9Lfcma5idgDh2r3QIgQ2XhHGDUyFGvcsaHyixsW3VuyIXx2POtzFJDj7d1zco="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkCexxACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqRZw/+N0y8WtMsFwhG96KofXB92bD47r/gy/YTuEx1fu0Fy15DzGlp\r\nrkmAWuV3ytg7vNpFlXvZ+5H8GuNzNVY95eb+jMLIwSL5n8A9RlIiOvd6sggz\r\nVkWPXIk9XOqZ8PstS852NUq4pUngiQjHNhlyeNySegQBqcDz3g3Nx2KEtG0e\r\nQ/XPQEfe7Dc3HtnWO8pR/83gEg1oPfZoedBAwrmQo9qi28Bwwvf8Cy0pDRyK\r\nfrUntWgq67PJLvmgVC0qlLHK5U81ZZh8yzZjz5zu26basp5XjXKRLAsT5o/4\r\npBRdfSXOpcySL9L6J2jJggf8qurxD+9e+HB+w+QtpBuEjlfxDDiYKQ8tfwnN\r\npBMy96hHX06kQnzn0+aD4nAejN0UdeuIa+j/2hhJOWJFAu0aj2rfZlbTTWc2\r\nZaqZp7Y4gDCNJM+Mwg6jM4qFZESmIaPGq56g+EyfmN4Gs0Xu5Zq7U3jpUfgg\r\nWufw+1BMRG9dI1gZ6JKxtNJfm2az6/E2GKj9eENNMRdMI5kNC+Sbb2qQMLNT\r\n0Ln6Oc4sUIUUIGiimr7MyWvjFExKNOxl0zD8YOzQdSZgwYTZt2PXajgFdzgU\r\nsHVZsGjIAHzHS+RcAYqERI1A9In/S6rEQs0iDpDLL2ZVGDleXXYaeOwvb1KJ\r\nQSzDAP/xy/rnVk1VZF7rQiS5adCKcELugYs=\r\n=kleH\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.6.1-unstable.3_1678371953249_0.290388983932526"},"_hasShrinkwrap":false},"0.6.1-unstable.4":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.6.1-unstable.4","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.6.1-unstable.4+9e07f47","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"9e07f47b14b7fb32265266197005b5f3bba64fc6","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\nFor onboarding the service in the **gx compliance**:\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.6.1-unstable.4","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-dQwY4Rsk5po2AuDtTHVUp2iz3dy0MC4LXLXIPYibnrRAGMiZ6I/Njm/eoetE0gMeNX2wpvxrvs678TVQXtWHcw==","shasum":"ada2ae83bf049c194f2f6332f6c1c6beb319af27","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.6.1-unstable.4.tgz","fileCount":47,"unpackedSize":390392,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICFyK1T87LzcBIVtnOxjxqHg7XmOXP7fmmtCc+Y4H59YAiEA4FAWTcVp3ih17PCDPIAmvDfMX5Su5pZdCJ7M9L9hjeE="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkCe6lACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmp1hg/+IB8mQbflvGkAur+ILdPXu6arlrXOS8Yh2bfVlUC4VtjbIXQ3\r\nKRFAmmQsXVC7TUCqO0wQcHaEeANgMRUdUwQLuArVKeWlStc+cAFrhcaFrC9e\r\nFjjVBJoHeRcMyFbfdLYXOefNXYlBTr5wZe4jwm2IZCHAoZVWbIuJcLP+pI4C\r\n0DcThdCRhdHMULWxXaPL3HqixywMpYS7NFC9KNpZeuRuX/ZulNcpoD7R+e9I\r\nCYxEFnOAojY/NoZK/oVaeS8Sdx53w/DmyEIIwyDLsy6ZBsUq7hSWIXbTTJkh\r\nLM8ictY2rCOU7dWo4DXy7X5Xx/sD3ofIHWqDBuGDouhQfs7FISTcDpaPMhbD\r\nwNvAdxyBJ5euz3BdbWDvbrGoQ6ZDlcoXx1mlzkFRTAub3yKHTFUGiqdG9Yxh\r\ng2ZwGNsc9x68cvjYfiy1Ut2Bk1jrBXmI8OsKYA6Ja1c2iCPR6oIuYIDKoF2d\r\na/auaDceQ8XIxUGdgv+ggBQU3aSQIvYOtM6Yu6aurWeDsCSU33QPbuwxYwEC\r\nqI+v0w3VgA02q/JNrLDDRXcMqv2TEZKATc/mvgF8vVbRlCXsF/W9MqzsXNmI\r\nJ3FJ5qFZ998JJ/FvaJRl7h281wLcmhRB+pgVR39Pdx7Sln1bASmhAelmDRDZ\r\nwNydAILUHpSeOvIyM3FfjoPG0UfBTuCn8p8=\r\n=QMh8\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.6.1-unstable.4_1678372517194_0.732811631526463"},"_hasShrinkwrap":false},"0.6.1-unstable.5":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.6.1-unstable.5","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.6.1-unstable.5+04668f2","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"04668f2c9cd57f1c6b051ca9f994ca438436e500","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\nFor onboarding the service in the **gx compliance**:\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.6.1-unstable.5","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-xcCxXM2R0PQwOXK1kkqkPjVhopkO2DgVmkhW3SYa32gCstPIGBF3WT1AgfoOxGSnFqATp4mhNLZGNvuqx+azTw==","shasum":"4380979c1abf65659c0b18ec3a982d95d2f20fda","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.6.1-unstable.5.tgz","fileCount":47,"unpackedSize":391759,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCV5dn4FQtJX/KyuBTZInxPPCYQDJUUTTHi8kXpljZimwIhAKCnDE+YT/Ygo1cCUZpHEfrMPYfnaPNYnSJiP4XzjHep"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkCfm0ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpJnxAAgP/xuc7FtVTxHxb8rTYIWRdgL3bsk3ZzLGURTSzT2gWTwCp+\r\n1Je4UAy+hTQjmgLn8Ls7r1JPRa83A1kumdP6YPLBC5wnzONWTuVhTDL/3hwc\r\nRgp8meUQ4Gd0e7QnmQ2tVGuLXDxkSqPVqlccfyLh52Wvy1frJ++CJHdU1KI0\r\nZTXGVbpRKOR+cZBp/I8NutHObbY6rZEL4xhHmQiWQy7JHFp0qoAn2Lq32tZG\r\nrPPqCipp844UIgbZaNtuqrDNnUxSUfGTvhTjXbNJ+PPiJgAhTBzAAEcnQMDW\r\noxZl+TK2ONzXV56Z8UtSeaZjw2YYfGrbZSVpPfiWdUsP5IQOTmzoDi4u0HKv\r\nunYz4tJShqFHRgHqN22m9A+1ETCPhLwrttvwGfDXYRg0ol4+BnWgNECVM8Qy\r\nki9K4IrwpEKa7FkxUACxFOM9ehauC/JTAbrZNUm6hQD4zWjoutZ3er0Gm0lY\r\nZYvQjULnSiMFkQeG96PZMMC4HN9j863XxE7e3CsebQxOb0Zs+SWM2syjjNn7\r\n6a2emOVOrfm6hcxf944PJc0i+o4UyAub+9OtoxSY69kaD/g0tuRVQ9JuKfzA\r\ntB1oq+U2xZcWJ493ne+PLYS4R3kQPBnpSS61ebftiSlRY0Etpc3cz19Qjj1D\r\nggPXda18oERREsvYdXq8J6n4m5nYkB/+J8A=\r\n=NUUs\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.6.1-unstable.5_1678375348019_0.07220980842666092"},"_hasShrinkwrap":false},"0.6.1-unstable.6":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.6.1-unstable.6","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.6.1-unstable.6+e2097b9","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"e2097b975a73a0b537cd390164b44437197f3199","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\nFor onboarding the service in the **gx compliance**:\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.6.1-unstable.6","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-iM/Pg8gocMaT5JdSOqHnf1+2Ub43fd2fnjPo//7AB8vRKFhYDj7YQwcMgooTellAjiJIoIVax/r3db7BGd2MOg==","shasum":"f48941208ed60d3091a69055a9516cc641892e39","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.6.1-unstable.6.tgz","fileCount":47,"unpackedSize":391771,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDcnd/+qFuCTlVHWE5XHsEhtYoTnscjvT/vosC9UIlsTwIhAMCW4p0eNjY0Zi/4urOr4zVFAorj2MO99uVVUTdgVryX"}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkCuunACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqiDA//VvSGPck/HoM3+eLICm1wDRmhVDlWAJFaTwTFUrOVXdr94+JD\r\nRIoDUk3Zqg0K2ZgJuNlt1e9dq0qxSkdYIWJyBhbABRmD5QuAsR6aDTe2DqSk\r\nBL5NCGhiblYaZB6wsiDZTwq+dn15xdO7Hk4P8l+7JEzdI2RHjgaZZNhFRQ0t\r\nVPxPtMkj2b8hIEs96Pk6SttP1RO0NMLY65Cw+hpqQoX2vHZUGUTA3APa9e/e\r\na8Lqubs7OeR3k14rLVQTxRSqThdU8xUwZrXBpjOY3WeZHlkfxXQx+bvVsYD8\r\nT9uLA69QUsM/dHBTutlNyoEDxDfTMbP7VyC0wZsF8EDY/rlDHtN0v8FBrDb5\r\n3rpqyynQsTGkMB41EdkkKrnhbAtsUwaN/wT1jiEkONKDv6wIb9x+UQ3tjbJU\r\nxo6ggwbFyfm1cOYRFpoMitgYd3024OYdky6g2KvnQMExmC0LoW2ipx22EQbm\r\nMt8kxNfmxwJG5Vea2zcOZtVSEDPVYvt5t4O7l+e4GCNk4eY1LsPdxQoZ4BaT\r\niOrUsW8JDBXKZP4iLoNfkGCb/Hdh/9hBMxE8o8dsYdovruVeLqLC/Xt+DO1C\r\nLD8SVYb8J1iKEPzz8DMwN2Alc4V1Bx00ZmxmGSFVLW1LCtjZELqDN6w0yc2g\r\n4GUZUmXkwpoScLTxNCkZAcZanKobIBOnayc=\r\n=Qh5T\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.6.1-unstable.6_1678437287607_0.757819375720352"},"_hasShrinkwrap":false},"0.6.1-unstable.8":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.6.1-unstable.8","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.6.1-unstable.8+2aba002","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"2aba002a1e87d22dceb0057aff0d5df61e1db3c2","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\nFor onboarding the service in the **gx compliance**:\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.6.1-unstable.8","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-iwafbh7oI0EwZ8pc5xSnRQA7VA8onYlj8+m2Y/mCrnT8Kxg0pScbBG4A41rKhczCBQXa6LmhRbsbuhRfBH4Dng==","shasum":"f54f99f3e6c93242e2a89506c1bf74355ec69a06","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.6.1-unstable.8.tgz","fileCount":47,"unpackedSize":391763,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCXW7incAOsEdNIlYWyj4Wr18ALCH84yL152MUcFEKnTAIgaW1/maS30m9d3z9qSrfah6r6ahQ7iIyZDDoGBMIfado="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkCv33ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmrESRAAkIYOx0C3QYw/WVniwYtfWt8bmt7aDowq7bso65IOY3NlbVZB\r\nSbX7ChXHLRsAvcsrOo6WE278BRTub2hJZKDFnv+hwGmzXmqiJE1NtiTsYw99\r\nQz04kABz1z2G0dRicKOcScAv2sdPffrbTq0uR69V8TLsdkjE2ngk0S/cscQW\r\nwARPMM6ObyXMzhDCK1tIhb4J7jLrAwUrEEHerxf4RTy3Z2HQzdsqZnJlhmlt\r\nvWmZ4NDtPXXVSZj/FYyZGlzoa86h5xzFUoglBkx/WsJlL5VdtXMEYMKHm3tj\r\n1Bwm7B9GRq+dT3M2u75GMyGuvZQTmtkNoyE7xhW8JtDzwWUh/gY3etsK9f0B\r\nr27tDV3ZfxBgAgEegTrxf9ORgpmXzYA1flUbx3NkfMqAJTGxcXEj2Vcfi/vs\r\njUcyXs0cqyzWw4wBcMfvwJN/IRKlVT11iR3cPThV0c69Y728FR3pyjWk5DyB\r\nYqOYX6MLTFUyykRc5U+NDvIfp7Wc2rNbpHYXSUJycMao0p4JpC6v8JMyODpz\r\nf4Y9wt+cApc2jMOCYdSQJssXbZ74l3ayqIEwg8n0SBWo6blhqBsTcEKQ39qO\r\ns6XcCPql7azT5lA+OL51pR5kr33yi662+VrdBj0dAa7ofRY5fH0h6LSEMVAy\r\nlpxj5/BOSJCLfZVy+t69kgdiSCRNCS2dJA4=\r\n=SBkT\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.6.1-unstable.8_1678441974975_0.7135836139354796"},"_hasShrinkwrap":false},"0.6.1-next.9":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.6.1-next.9","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.6.1-next.9+03fc3c6","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"03fc3c62cb28c113283b7256250af141febd8cef","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\nFor onboarding the service in the **gx compliance**:\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.6.1-next.9","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-GilgPVqLpHhKS50mf8Je58db1YG+B8NEhPH1zD98t5l+9H6CkfYAUtHZ52nkumdnSpsjn9MQ3QAI26M/WmhAeg==","shasum":"3f390e8ea09f8cbf5ede7bd24d0befe6c0772656","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.6.1-next.9.tgz","fileCount":47,"unpackedSize":391755,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDNMbHYgf0EgTn+2afEO6V0gmkqFDosF/JM1FyTKBm7xQIgHvUpt1+8+mT/UedikDHdo36z62U7rMHqZQdlU1IHtV0="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkCwhlACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqLOg//Y6VUnbe8OrJsctMA1oT+jJ6sX3dyHRdUlCsK9+7PViT7HpBG\r\n/JOtaS5Dmh1NonSLsvf6vYc3usBjIO45+nYNJ4U61XqudNT1ym0VS7BnjSED\r\nzasDZhmCRFDusjqVCQsvDmGxlU9ATnJmCzCfpkBqouuTkCaTnkfnztdBM1xr\r\nCGFKvGtjqESAqh30vQfHan7pMZCv3DJgaXjFiNOIUTD7KOQUvjfBTkPQl9XJ\r\niKcKipuTMjV2SG0TFLcaw8Q17QBfdkVgPUF8qevbFFO4jM9vqDJWyIyDk9yI\r\niaO+Noxu+MJyR04gsUECjbHsHg6Qwr3IaqkFvcP23MjZw7Jq0ixzsdo9cr85\r\nkD/NLMHT2gn8L/l5uIqgbVk1gJuPGUW4qMc+QsoJPEY1+kWG8C+OVWUiBEUc\r\npafaAZJPysfSvxSm4D5P30NLLwnXmJpADl22ytw/ER1xTqM+v4TkS2ghxvnG\r\nHfdDR5BxkAReLPHEv2XV1hTXowfHuCelfVLDs4sEvCl9kIf4nxqemxEYuT7k\r\njnamRxnE1JrQSXyO/y2fCtQdkzsyVFuETCucqBGO342HakLtCeBF5Q9oOpoj\r\n+XZhJR6mG3YZ1g704Bgy2ZBnyJ683AE9oGnOxPnitQdgDY9EocW/Pzju8IjI\r\neM6hbFxGtXCGxCdEHNzOWo87iMdFB9Imc0Y=\r\n=3Mq4\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.6.1-next.9_1678444645205_0.027973491613886958"},"_hasShrinkwrap":false},"0.7.0":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.7.0","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.7.0","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"ceb8fea46efe92d28fcb318e2546e269d02ea02b","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.7.0","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-NEAmGLcPOgb3enNBlXeskmFWGFGYJcypyRTVQi/P3CQ2+69lFsN6GI4TeADH/zxofuTgtRPCuyyvZk3Eqw3Oew==","shasum":"1a6f2c081f4f10fb9712244f2e6dfb770b6be44e","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.7.0.tgz","fileCount":47,"unpackedSize":391725,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDMfF1TKfYsLgP8r2ZcOcgAEp7fWBYUl47Ehh8rwTHX4AiEAu4dKATkDv2SCmvQAMZQ3eKwm+bLWyDTyceJqgjg5bkU="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkCwnUACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmobHw//RXGFQa1ZmpQncgmPLYVv1wKIuoFfvUpVEWK6cNAeS+eroFSP\r\nyCZiQirM/fwEgZmBiCBUCwNnnXPyXufZMNcAsOJ+rzQDRX7xwO3MkBd4v+Zr\r\niy1BT+NLUK9uvFW/Qcg2gg95D28wonqnoFZ9bU2RUSMV0Iql79lpDxAEbAm1\r\nn+3aVx6niV3Bkixb30hbtzVmtuMdW5tMnjxmxECqPUfXEGvYzNHYYgLBlHZO\r\nSPJrUBuchIgyjMpqk3rP+g+dXoLerc2z9lM8T4CQC0pX2cNcS2/zlKTPszVK\r\ncKvdlKEw/UxvqCgZgZN8cev/SLv+Wyb+yKDVup6Z64EHH0xs6aYKGeemS3Pz\r\nhQUme4Z8oOTOMT/3GrMq35kQsif5LVe1Cbg5HsP/aShuGett4A2BR64Md20k\r\nGF9e4cd+v6H+9ltyMHzG5/qNo/XwXPwj/y+lx4LEIy8f7vmisRUTRFX8jIY9\r\ntjPObgV4Fv9IM7VKOkp6vObXns9gWLUb5g/IxyurBU5mo3OFIeT7F8HMfmGE\r\nrpGLq1s5zpVaWi0oGGZLKp0gUraDNTaxNVT+w+aNDNgv7mxa6usHFdASRQPg\r\nBePrEqONmN1NrjBxbHFgDnVMS+JLousX2DUm5fVPtfZb0RrPWsyuoU0VVstN\r\n2EWiSHHLweAFMAAPrHHJUB9LY5JSJ/Cyg2s=\r\n=K0kd\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.7.0_1678445012673_0.5470925266098392"},"_hasShrinkwrap":false},"0.6.1-next.11":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.6.1-next.11","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.6.1-next.11+7ef1cbe","@sphereon/ssi-sdk-did-utils":"^0.8.1-unstable.242","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.8.1-unstable.242","@sphereon/ssi-types":"0.8.1-unstable.242","@sphereon/ssi-sdk-bls-key-manager":"0.9.2-unstable.18","@sphereon/ssi-sdk-bls-kms-local":"0.9.2-unstable.18","@sphereon/did-uni-client":"^0.5.1-unstable.1","@sphereon/ssi-sdk-did-utils":"0.8.1-unstable.242","@sphereon/ssi-sdk-vc-handler-ld-local":"0.8.1-unstable.242","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"7ef1cbe853ae7cc59d2ba59d152ef46165f46ee6","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\nFor onboarding the service in the **gx compliance**:\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.6.1-next.11","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-NZUiWlXmw0UUN9FVqoR12Qhp9C71SXn7wwAtDBws1UThr9yG0p7PGpNpcTX3JP+DtvQtIuV7QflM6M+U2/DcvA==","shasum":"4595ea743925023f7577c07533d2431fb13391a4","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.6.1-next.11.tgz","fileCount":47,"unpackedSize":391757,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIB+XV5QOIMnjSYCAOac2EWRPBYQ9jA6uVQ7q0Vnj9TGlAiEArnSilDJkJBH/qMAMfWaYerpMAkGmCttz1Co3MkmWtD0="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkDyLUACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmpuIQ//UKDTiKLF+Mqm6RY5dvK1pJjJbKJ8tq/2j/++K6WQ1b0/iPXl\r\ntsWL6NgG+iX92gfLkLIqGyv2K7rhHj7o90cmikBEN8EnrQsBl3KY9dXDxa6g\r\niQEvZGH9zAENhT0jzsLfp8pe51mbl7YI7uIazKo5uyVcTkWqIgytN3gNt2Be\r\nuItnP1JHx1VuWjG0zjuhIFWs48ZVmGSPGN2YYDeHpJCA7sbfJPhCSLNK89P/\r\n3tsoFRNXteJh1r9FgexDaeTP62djrYuooeLOkk+8yOurkvVSlfG/Wz1fc1AH\r\nXCi58cnlTPQdn+6PukUtBZ2gJ+dAUAXasbdIA9H+EgGt7HnMMyqEhG5sO+YG\r\nTa0TTlnDMvsmQz+K3naEklYzFlj3CKlHbGPXZNqBOXuVQeX1WknEfiFgfSq5\r\nD0x2No8JcVWIDfUXvozWV7V4JIyvJqTd1WDqJWQwzh5EYh8l+I4MmMJhYPtx\r\npvSjeHndQWZR0Wqfk4UPknzu/rvTWqrmdKHWo/CQCJ15VgFJPuLbBcbwf1wJ\r\nhUa5wiprBaY5w3g6emFoZP0pObCs/74e+64nz7NI6BAbsGD/YonHzNa5S1hr\r\nGa0/0jw4N7TQsM+8UOfTuE3TAMBPxIW7znUDTcGnleO8GYcy147E0hhy+0Xk\r\nbgGb7Nw7/i3RlIzZ45UGihZ0iu6rBR5ZiMQ=\r\n=0w2B\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.6.1-next.11_1678713555776_0.7070069273670521"},"_hasShrinkwrap":false},"0.6.1-unstable.12":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.6.1-unstable.12","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.6.1-unstable.12+4f4e35a","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.9.1-next.17","@sphereon/ssi-types":"0.9.1-next.17","@sphereon/bls-key-manager":"0.10.2-next.2","@sphereon/bls-kms-local":"0.10.2-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@sphereon/ssi-sdk-vc-handler-ld-local":"0.9.1-next.17","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"4f4e35a6c7aa06de8bb81b8e52f1c7b88af6898f","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\nFor onboarding the service in the **gx compliance**:\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter  \n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.6.1-unstable.12","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-iYbAjRsueNChw6RX/vZYemE08OON8QVC394sXQ0YbZ/7JEd0fcWMKEfQUeR3wy1tBhiekm9InXWI6bzlGz2e+A==","shasum":"cc1dd7f1e8e5be04f8bfc453760ddc3bd317ab5c","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.6.1-unstable.12.tgz","fileCount":47,"unpackedSize":386317,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIADsBRHHwwDAgNlp4Q7Eb21dCWKmR+u9fAD5ZheFAbHTAiAmjruxqRj+CvLgq5CYPA39tEDLFXCw7iwyN0KMyU/iNQ=="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkFH1RACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2VmqiiQ//dKQoAiocd918Fh7CNqMHGP4oPhbtV4KlNEUfNKpxsEZ5ojMI\r\nqGWg0KhTwoJzKU5fvCGMSbnLP7Dqefx3CnKv3XWVuJd78LlMWiytJPIHnbdM\r\nRlcgSJYsLAtcY9y/Va3vccACmfi6OIC6Odfmab0gwkJLIDQLdLJFw79IgenW\r\nae9WDJ7Qs3hEUHEoem0o4g3A5VMKMI93Bq1bf4w8NaLJO5UVIj8sGXGbJbxD\r\nS0P6uqhr2L3uiEQ/57hoFq6457e7RzfmHVLoyGqKIM2pbdvGEO3olzXh7TwW\r\nnVmKj8ycy4J+AhPIXC8DzzKbhGa5e3QDerWBNGhFzqXqvhn4wxU/fsDlUhek\r\ncQH0p/9l19Yb4L7UttmH+fN36QJIuhUhNiDghheqdfXVF0yXuoSCMprHh4kE\r\nIKsoWFobYq9x1xcjgrGIOjLcRYmBiHMZ75Fb5IJEZQNdTvFhaFjmCdrQCmeh\r\nHTUKWByswqR1EY0GbWcEKZC/8MHFmEi9p4JK42MV61CByP4IpMOQdfEzjuoq\r\n554R8bYdFrW0g/M5c9l6v2+06hVOPpVpgTyHtzL2JAkw1lWQmTyZHIIwX3oc\r\nfVJELU7doBKjnRWswKxMkOoeXl8euPA0G3aHJdimcNV0MRI3G+miQ78c4ReH\r\niFk9J5/z0BcxF+Hh/IVY8swBZY8YiiY9Sec=\r\n=Fr9b\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.6.1-unstable.12_1679064401474_0.2442064599368905"},"_hasShrinkwrap":false},"0.6.1-unstable.13":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.6.1-unstable.13","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.6.1-unstable.13+bca60eb","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.9.1-next.17","@sphereon/ssi-types":"0.9.1-next.17","@sphereon/bls-key-manager":"0.10.2-next.2","@sphereon/bls-kms-local":"0.10.2-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@sphereon/ssi-sdk-vc-handler-ld-local":"0.9.1-next.17","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"bca60ebf837a22c74c5c6b66622c3015c8ed28aa","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.6.1-unstable.13","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-raoFm0xn6bdQye7+Cb3kPiEA08zBKRHYQUPh2kR8R0jjQOTVe4qxB2bQaDpV+eKg5n5bGh06gh5GoD4bsmsRtg==","shasum":"f9545634ce537c6e74ad4183e1290ed5100f3e28","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.6.1-unstable.13.tgz","fileCount":47,"unpackedSize":386320,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICdBNgx4RicwoAuWYVMR4h/nIdfRF3GZWcfxOjIj/TWmAiEAlgaRxOR19k3inw9+sigg3vVJ5/NOfXCEv1db/6UwJp0="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkFH15ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo+qw//fJr6JaZVETU2/4XzpPqiToKEDojLvIdq8ijKpQOj0kdAZtnQ\r\n//V2VJXjIKFxhUe7SdgPCdqN4JiCjckO0EnX6+kTWB9969GFzUK1KlsGadt9\r\nnqe5Kk56TFm3tr6dw3oN22PINFKzVwnMMjfla4kXF0Q9sJv7ovdfSxz6CyKX\r\nSLJfUNvzSvUlnbOk6iYMVZEWpn5vPr6o9YWq+Dm+6FazCCkBm6QHepU9EFDI\r\nRFltymxdTaOkjAp0+NSzh+sbQ3XjOaTFnOlsVDhPLce9J2BIz8rRyzPHHfqK\r\nAphcHV6niCh0QDMaIfDoHPoYtgH7+dNMnHCh0hn9wojzxzDaRU6SXjum3H9B\r\nynXE0yhzPUlFqx+lG85xk3xxcyvH6Yq0btHs/LjVyxNYsdYw5uSA6CnFRb6v\r\nAVsAji+9YiC/NeQRhuTKAH7QWxFUAklKJJKlR3TVY74X0XdLchhL+Za4Sarx\r\n5qQnP1tE/tqrl9m0mlgLvqLmRUbJ1wRXYqdp6PjkovLO8qzuwIeOUJLnLlmc\r\nG0iqd65u02aDOoOVGTNUgKh9Z/sgalXa36UivSWWodX3gz0h3/43ApGTDggK\r\nxsw+3dnvWgGT1j2eCiG/+uf2jbcFoWWS8lmSt8n5HYmbiVp3Y7mM15Nah8ML\r\nThGlFd2W+zpfMnwqWTxY3w+5Nd4OfzVNa/A=\r\n=PbJF\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.6.1-unstable.13_1679064441413_0.23811027603628498"},"_hasShrinkwrap":false},"0.6.1-unstable.14":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.6.1-unstable.14","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.6.1-unstable.14+f18b803","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.9.1-next.17","@sphereon/ssi-types":"0.9.1-next.17","@sphereon/bls-key-manager":"0.10.2-next.2","@sphereon/bls-kms-local":"0.10.2-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@sphereon/ssi-sdk-vc-handler-ld-local":"0.9.1-next.17","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"f18b80390f9e9eadefa8009d9a110a072ca617b8","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.6.1-unstable.14","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-ZYzCTS+lp3f6u1Bak5MNBECw75s9psqZiGZA9LCb9/yxyDA2740m0hefIF69g+Hu43LZTfaBPiyXW1wLpPjHqg==","shasum":"bee334c6362e420d9fda2056d9956c2b00968e7e","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.6.1-unstable.14.tgz","fileCount":47,"unpackedSize":386320,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFVPq6NadI0/LtKhvhtf7sDnw/1Q0aVAHGXmufo7JctOAiEAzFmSJO0YOkh9Hw5AN1VLPqRY0do+g+vlvWfV46M8Riw="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkFIQ2ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmo4bhAAnfgyTblf0dAKFkNBWTzG6zIaCf0acJxhlvaOyP6ETdkAzFqF\r\ntPlkYKM7Rx79KfV1G2YhWqgVHdEvDosXXNbm9lJVpiBwJhhcEI0iSq9cP/3C\r\nvDyM2GAi0JN79WEYWzu4Q835itJJ6IBxKqbsbRs5DBg1KIJESyjx17KJ4UeO\r\nShFoyghocg+xqpsYA9hhRKXa4BtoPIJ99LYN0tYIjw58Wgb+uETxCcD4oBTY\r\nIz99vPxliKZeq0TGD0XIBdcz8uWrNZ/xqPQw1KNYXj76lnPzDL66a4OYaDfr\r\nmQw9pMjj2X+7hbU20kACRtJa89YGtLL0+2zqJnAMDT6SYytlwZGbyEjtD5mn\r\n30f0D+WoskznsQdao3mbgBlL4JVIOw401M4QKGXKd/t8kODDGZA9d9jLeW2r\r\nikplxLd3C+hNXO4F5pSgGAtCIPfn8P7XVsvgWig6n/XaWb6AVR672CpOpCxc\r\nyjQ14jCzcEQZeEGqIK6f/kuTNMVVThNR53oa3eQTYVbrVhtQDwlPgU8wwt39\r\nTnoJ6obddlws2xtifrFIThDpO8WqssqMDeXe627vipjryKZLxmIVBNyK17pK\r\nUkakxq7tWjkijF+8UQF82IZeFzxr2+bX8uvADgfeYQsiAvWnOSyChN/0CrQ0\r\nxXsGqritv6ZQ25Qvx6bhffI+z7mPJTgIxuQ=\r\n=6KEN\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.6.1-unstable.14_1679066166706_0.6711555259063566"},"_hasShrinkwrap":false},"0.6.1-next.16":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.6.1-next.16","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.6.1-next.16+7181434","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.9.1-next.17","@sphereon/ssi-types":"0.9.1-next.17","@sphereon/bls-key-manager":"0.10.2-next.2","@sphereon/bls-kms-local":"0.10.2-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@sphereon/ssi-sdk-vc-handler-ld-local":"0.9.1-next.17","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"7181434b2d72e220578aefb2b0f87761d8ba0df9","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.6.1-next.16","_nodeVersion":"16.19.1","_npmVersion":"lerna/6.5.1/node@v16.19.1+x64 (linux)","dist":{"integrity":"sha512-8o+iiV5gczbQYsavXnYWDRtCRfH1xycdMRhs3THE9eF2MP4uucUOCcjOJdKAtFbD8sirCv7hPXrFv0uS8FJYOg==","shasum":"cf0dd18694a6e9607acbd27913f8340f4bd4ee6b","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.6.1-next.16.tgz","fileCount":47,"unpackedSize":386312,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC7ZE/5Z+4xUdCf7c3N5Ql1u/2mtctG3ivpoHBCQX7g0QIgFYEH32SP1DdTnUD56azfuLQqE8bcp8TcgzaR34UHt7I="}],"npm-signature":"-----BEGIN PGP SIGNATURE-----\r\nVersion: OpenPGP.js v4.10.10\r\nComment: https://openpgpjs.org\r\n\r\nwsFzBAEBCAAGBQJkFKI4ACEJED1NWxICdlZqFiEECWMYAoorWMhJKdjhPU1b\r\nEgJ2Vmomfw/+OoyazAhWB2Yd/4JJsfGU13zozGkNc1/3Ifc0yQtwlELw4b8S\r\nkpTqJhIOF2LyT657Ddy2BbjIHynEwl9q7UaIPceDRojrpGA3qVFoKj0hAM+9\r\n8M9n4LYkuliFSewJnq5Rg08f4L7pSk0V8TwBhWO7tVAbmY9/kEmy8FAWMwuL\r\n2WHwBcspPPCV9ypwTCZSa71luUgaKj0fGiKXJaQN3BA2QkHVih75STr/fwDe\r\nNlfOmqRswxe884SmKfz4X7R7WVnoNZV7pOHdPRNPH7hzKqUR1c1swQGQrUBd\r\nHyduL9ueS0Bd0hxly8u9gmHtliZsDsN97Pst0TXLB8xzoVg6cxhXgNmIloRb\r\n9xXKY8id/ml/DDuOHKuYBpsnv0n57OLGQhbeEm+leebZ5fSi05Q1pX87pHK6\r\nvPb1JI127hG1SpOSzxsIHyIlGOS/DgGJ4eOK8aR2UeiDtF8kAUzz+BoEVXWZ\r\n836MEfyE9Q5uff1xdC+dn0NPaM5w5KxPmmE4fkRpIKA4jqe3sF4GpYoYCiGl\r\nZ+Zz/0o5ma/0j/AvfOjjZw2r9BgvhgNvAA/79qaT+SV4Cd/s3pHot0mFcAZG\r\n89N4tbhALg7RJqdF9EKHcJTqBIJP46aYNV8Ir4O+RXVf9SkbgMKF+5B+a2Hb\r\nuDAzwSyXS5vm8lTqcOqrnKHLjf8IS/DgSGQ=\r\n=C1tu\r\n-----END PGP SIGNATURE-----\r\n"},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.6.1-next.16_1679073847961_0.4761619535128223"},"_hasShrinkwrap":false},"0.6.1-next.17":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.6.1-next.17","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.6.1-next.17+2949bec","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.9.1-next.17","@sphereon/ssi-types":"0.9.1-next.17","@sphereon/bls-key-manager":"0.10.2-next.2","@sphereon/bls-kms-local":"0.10.2-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@sphereon/ssi-sdk-vc-handler-ld-local":"0.9.1-next.17","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"2949becc5d6612d5d48322ab630b25fe00f0cdfe","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.6.1-next.17","_nodeVersion":"16.20.0","_npmVersion":"lerna/6.5.0/node@v16.20.0+x64 (linux)","dist":{"integrity":"sha512-Fv6/9WYYgMs8QwnP9N21t0oIFs9esz+FtFJbwYHwwQsLNwpG2BTTieb7ZLK/1fsBojJp2+19ik65u5RCxsYcRw==","shasum":"a58e2f6d7f104b42f424dad257ff3554a7a983e8","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.6.1-next.17.tgz","fileCount":47,"unpackedSize":393057,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDuszESUd61QYhrPBTOLMNn/0+J3uvhau6LU+IygkpfggIhAKub9AYGll+RZn32cuwa7ElGos1R7l91YGW9VUGLsLG0"}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.6.1-next.17_1684885277875_0.03226739650721511"},"_hasShrinkwrap":false},"0.7.1-next.9":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.7.1-next.9","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.7.1-next.9+94e72b9","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.9.1-next.17","@sphereon/ssi-types":"0.9.1-next.17","@sphereon/bls-key-manager":"0.10.2-next.2","@sphereon/bls-kms-local":"0.10.2-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@sphereon/ssi-sdk-vc-handler-ld-local":"0.9.1-next.17","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"94e72b9f660026be8a1c81a5bffc40ebc4d7eaa1","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.7.1-next.9","_nodeVersion":"16.20.0","_npmVersion":"lerna/6.5.0/node@v16.20.0+x64 (linux)","dist":{"integrity":"sha512-SmdmwNJEE6e+yZwpj9lqWBADypxhOL8YBMhlG6b0hmO1R4fzMiVhsHvmKbI1j1YuNsCrgXbp73SecUV45XniMw==","shasum":"f1a5c885aeb793661ea2a76c82647541bb45968d","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.7.1-next.9.tgz","fileCount":47,"unpackedSize":393055,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIHaTF6GzpXWp0+b5P2ucdOF5EG5BQHtFL+Vy30qx29y6AiAHohsT2wQX5QzH/6keBpxDx62m0QzvdSzVykfff7b7XA=="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.7.1-next.9_1684885651785_0.03334863877278105"},"_hasShrinkwrap":false},"0.8.0":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.8.0","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.8.0","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.9.1-next.17","@sphereon/ssi-types":"0.9.1-next.17","@sphereon/bls-key-manager":"0.10.2-next.2","@sphereon/bls-kms-local":"0.10.2-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@sphereon/ssi-sdk-vc-handler-ld-local":"0.9.1-next.17","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"462cc45108dab367e2f9a67c364c17f697e78896","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.8.0","_nodeVersion":"16.20.0","_npmVersion":"lerna/6.5.0/node@v16.20.0+x64 (linux)","dist":{"integrity":"sha512-2E97y2LTy5Wi2U+zrmM//68PxF4Pu5qfDG1HFScRPGqKrcr27vbVek88E5pFR1TLxE1J/OiJqY37z6/v5RhPfg==","shasum":"a7752f0b1d63f3192cf835bd5bc926c5bd38ca63","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.8.0.tgz","fileCount":47,"unpackedSize":393025,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFw6V3N4s5Bc0UsMYAbxCkjuDpt3j5IT7XFJExCE7E+xAiEA5ApN7XCDVC3++mGrI3Ya/fqdDT+H0hhctJaffKZzXY8="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.8.0_1684885919120_0.9737069451871863"},"_hasShrinkwrap":false},"0.8.1-next.1":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.8.1-next.1","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.8.1-next.1+2d0f0c4","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.9.1-next.17","@sphereon/ssi-types":"0.9.1-next.17","@sphereon/bls-key-manager":"0.10.2-next.2","@sphereon/bls-kms-local":"0.10.2-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@sphereon/ssi-sdk-vc-handler-ld-local":"0.9.1-next.17","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"2d0f0c4b8388cbee8022cffa515c0dc73f3a2b06","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.8.1-next.1","_nodeVersion":"16.20.0","_npmVersion":"lerna/6.5.0/node@v16.20.0+x64 (linux)","dist":{"integrity":"sha512-ty8SKDTxzDX8BJhzXJ+GiMqcNZhAB5tK9V58xq5jQoOp2ph35BAOEQzQSHRpXPbitWb+jx8VjB7pQ8wyrKnflQ==","shasum":"aeb7e1b08db6a0ad1ab114e3feb4cf0c25168f29","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.8.1-next.1.tgz","fileCount":47,"unpackedSize":393055,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCyQcQBYCCnSSqVKCMJey/VhPaawuHyDxpByw2/ucpAKwIhALmAT5xuqCWJhcsXpqTVZJXnVldnMnPuvANdc6pMEPRq"}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.8.1-next.1_1684888516726_0.38969365418316104"},"_hasShrinkwrap":false},"0.8.1-next.4":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.8.1-next.4","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.8.1-next.4+977183b","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.9.1-next.17","@sphereon/ssi-types":"0.9.1-next.17","@sphereon/bls-key-manager":"0.10.2-next.2","@sphereon/bls-kms-local":"0.10.2-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@sphereon/ssi-sdk-vc-handler-ld-local":"0.9.1-next.17","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"977183bdfbac5ab86d4acc30f0e4abdcf3f37419","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.8.1-next.4","_nodeVersion":"16.20.0","_npmVersion":"lerna/6.5.0/node@v16.20.0+x64 (linux)","dist":{"integrity":"sha512-UXbZQvS7ZaPF7VTX1UsdkCEV5p3SJiic4m1DKLtrdOFxCrnWJWYHZ4sUJAFizrW/4prbaIVFQO9LiwDjNJFk5A==","shasum":"04bc6d99fdbbab0f4efafdc79597faaba29deec9","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.8.1-next.4.tgz","fileCount":47,"unpackedSize":393107,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCKPkG9Jy6iorCG8NEqOpAUm12MXIHzb97Sq6kUFzLujQIgFAHvpDB5oEIQvQNIjoP3YNHVBGrmwtR5FJz3HRE5ANM="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.8.1-next.4_1684890563131_0.23159030755277765"},"_hasShrinkwrap":false},"0.9.1":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.9.1","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.9.1","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.9.1-next.17","@sphereon/ssi-types":"0.9.1-next.17","@sphereon/bls-key-manager":"0.10.2-next.2","@sphereon/bls-kms-local":"0.10.2-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@sphereon/ssi-sdk-vc-handler-ld-local":"0.9.1-next.17","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"68ba67e3796b57a646b48baafeba6e2a5ede7d50","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.9.1","_nodeVersion":"16.20.0","_npmVersion":"lerna/6.5.0/node@v16.20.0+x64 (linux)","dist":{"integrity":"sha512-K82UJtFRsUfQhnt1vlWmP4kpoNs+JWzlzfHVfYRmRzQA51ASVr3SsCP3AlH8W5X+mzY74y37OCCaajXu1swczg==","shasum":"088e54adcef12d4ce65a048fd14424ba0aa014dc","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.9.1.tgz","fileCount":47,"unpackedSize":393077,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIAIvoW+2dP60MFAiqTHJ7GXrqQlODYPVvLWi7u5APvNVAiBqIq6ov/INgHtMv0HUfTsXGu5M9+v0BaGuLrnSvwmzrQ=="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.9.1_1684890800238_0.9316564879219109"},"_hasShrinkwrap":false},"0.9.2-next.1":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.9.2-next.1","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.9.2-next.1+161474e","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.9.1-next.17","@sphereon/ssi-types":"0.9.1-next.17","@sphereon/bls-key-manager":"0.10.2-next.2","@sphereon/bls-kms-local":"0.10.2-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@sphereon/ssi-sdk-vc-handler-ld-local":"0.9.1-next.17","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"161474e3ea34f6649b6547c470bbd8993a65424d","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.9.2-next.1","_nodeVersion":"16.20.0","_npmVersion":"lerna/6.5.0/node@v16.20.0+x64 (linux)","dist":{"integrity":"sha512-W0cNuGeIxFB4LI7zgRVysa//Ck3NC/aNblqxwu27nHgU7+w47+asmvSvkxL0u92FlikImPLYnlMlKn3HVxBGLg==","shasum":"7768316816bf3b1959253a0097a24c76846b0a04","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.9.2-next.1.tgz","fileCount":47,"unpackedSize":393366,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC+LJGy0Rv6PGuQNkLQnzknYOkEWCoIHBFrpweoeccN6AIgOQTQYtEDDvRAJ17np4Xn/ENzu2R+vvrjaGLmpEDP2f8="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.9.2-next.1_1684893311211_0.12199038637047122"},"_hasShrinkwrap":false},"0.9.3":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.9.3","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.9.3","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.9.1-next.17","@sphereon/ssi-types":"0.9.1-next.17","@sphereon/bls-key-manager":"0.10.2-next.2","@sphereon/bls-kms-local":"0.10.2-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@sphereon/ssi-sdk-vc-handler-ld-local":"0.9.1-next.17","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"dd8d2513d4fdcf83166b8a7a7656e8c167cd8f87","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.9.3","_nodeVersion":"16.20.0","_npmVersion":"lerna/6.5.0/node@v16.20.0+x64 (linux)","dist":{"integrity":"sha512-GNfMmGgu5/pCcVqFXSgREg2s4e7Dnxt2wexuW/oUqH5uoDqQ/gV0SSf3+sZ51Yxi1tlWU4TQHJCt3sTor48lFw==","shasum":"00873cb35e92921aa80e2d4e22964c995e8bfa66","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.9.3.tgz","fileCount":47,"unpackedSize":393336,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDrJVZC7GJ+bKOFGlMi9Z7i8WyISl4N8oKMMBCSOdCQlgIgRW+fSgcdiFF2C6pRfCSyxAxx7rWqgX3qTbX+KCroMOA="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.9.3_1684893552552_0.08251055981837685"},"_hasShrinkwrap":false},"0.9.4-next.0":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.9.4-next.0","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.9.4-next.0+3e8587a","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.9.1-next.17","@sphereon/ssi-types":"0.9.1-next.17","@sphereon/bls-key-manager":"0.10.2-next.2","@sphereon/bls-kms-local":"0.10.2-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@sphereon/ssi-sdk-vc-handler-ld-local":"0.9.1-next.17","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"3e8587ada8f6ca37d69f4ac917b7249370abb58b","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.9.4-next.0","_nodeVersion":"16.20.0","_npmVersion":"lerna/6.5.0/node@v16.20.0+x64 (linux)","dist":{"integrity":"sha512-jWxtSMM/OAxBw7795r1chR7NgrObO5mCqyxN5katOP8WCnskHKkX8M+V5CRHrPXQRAwbmYp1d/fZU7+PijEBhg==","shasum":"64c700dd77c0c4c084ed05da2a8601b50383ecbc","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.9.4-next.0.tgz","fileCount":47,"unpackedSize":378891,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCICq15l4BpGlK46z1Nphw8y/ruUjJK/NpOlNhx+qKSVN6AiB4Nwsd2t/MdzYfzqClhiRvnJvKgUptRcECmrgjWm9Seg=="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.9.4-next.0_1684968275162_0.26682911226880424"},"_hasShrinkwrap":false},"0.9.4":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.9.4","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.9.4","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.9.1-next.17","@sphereon/ssi-types":"0.9.1-next.17","@sphereon/bls-key-manager":"0.10.2-next.2","@sphereon/bls-kms-local":"0.10.2-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@sphereon/ssi-sdk-vc-handler-ld-local":"0.9.1-next.17","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"17b1d7f57c2784266c0ad94f0fe1b2f801f24e01","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.9.4","_nodeVersion":"16.20.0","_npmVersion":"lerna/6.5.0/node@v16.20.0+x64 (linux)","dist":{"integrity":"sha512-QnNAqMNORF9ONSMaFzc8QL/3NfPN46gKsqHqCIyh4GJpcbRG/wIH8+EIaB30e1eOjtkW+gagsErQgoA5GgZ+JQ==","shasum":"fd093cc464c8bbcd0499f03304715aa982bf23eb","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.9.4.tgz","fileCount":47,"unpackedSize":378861,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDB8fgLIcWV4EN1EZznaIn2jrSJAnJjX4Ahak4FNLVxRAiEA+Mfho9Ca2lKpgKKvYH0EI4eckBKESsSBFN+4RpomAxY="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.9.4_1684971113882_0.2212763278964367"},"_hasShrinkwrap":false},"0.9.4-unstable.1":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.9.4-unstable.1","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.9.4-unstable.1+aeab2fd","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk-core":"0.9.1-next.17","@sphereon/ssi-types":"0.9.1-next.17","@sphereon/bls-key-manager":"0.10.2-next.2","@sphereon/bls-kms-local":"0.10.2-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-did-utils":"0.9.1-next.17","@sphereon/ssi-sdk-vc-handler-ld-local":"0.9.1-next.17","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"aeab2fd8446c6fa56b649661de915548c1ed7098","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.9.4-unstable.1","_nodeVersion":"16.20.0","_npmVersion":"lerna/6.5.0/node@v16.20.0+x64 (linux)","dist":{"integrity":"sha512-4b5P/EG2W+1M4Otqr+foqT4ZTHmNfBNIGZpQiE5ujPa7LY778PTV6+Srlnd0zvYz71cyxcoapHqqfMVXChKZkw==","shasum":"86d1d0930699b65d7d4e3e2c6d3d3c8a51c30710","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.9.4-unstable.1.tgz","fileCount":47,"unpackedSize":379135,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCRL4jy9DakGLnuLQhiBgg1JzX1+kxCUpYG+Yq8pBBWGwIgAsGUqX3VrlTbZOZPcITU7uivxjlkcTHkfPRy7YVUyp4="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.9.4-unstable.1_1685120858280_0.9703871134769921"},"_hasShrinkwrap":false},"0.9.4-unstable.2":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.9.4-unstable.2","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.9.4-unstable.2+145087f","@sphereon/ssi-sdk-ext.did-utils":"0.12.1-next.2","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk.core":"0.11.1-next.70","@sphereon/ssi-types":"0.11.1-next.70","@sphereon/ssi-sdk-ext.key-manager":"0.12.1-next.2","@sphereon/ssi-sdk-ext.kms-local":"0.12.1-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-ext.did-utils":"0.12.1-next.2","@sphereon/ssi-sdk.vc-handler-ld-local":"0.11.1-next.70","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"145087f53b3ae8b762917cdd142fb2a6a3ebab47","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 16\n\nPlease download NodeJS version 16. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v16.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config          Agent configuration\n  did             Decentralized Identifiers (DID) commands\n  vc              Generic Verifiable Credential commands\n  vp              Generic Verifiable Presentation commands\n  ecosystem       gx-participant ecosystem\n  participant     Participant commands\n  so|service      Service Offering commands\n  help [command]  display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `-s/--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v2206\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"@id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"your legalName here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"your legalForm here (LLC, LP, Corporation, Nonprofit corporation, JSCo, ...) \",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"your registrationNumber here\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your Country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"your country name here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"your gps coordinates here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"your street address here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"your postal code here\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"your city here\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -if ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"814c51d6-b559-4f7f-9481-b58a4c3bccb0\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:LegalPerson\",\n    \"gax-trust-framework:legalName\": {\n      \"@value\": \"Sphereon BV\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalForm\": \"LLC\",\n    \"gax-trust-framework:registrationNumber\": {\n      \"@value\": \"3232323\",\n      \"@type\": \"xsd:string\"\n    },\n    \"gax-trust-framework:legalAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    },\n    \"gax-trust-framework:headquarterAddress\": {\n      \"@type\": \"vcard:Address\",\n      \"vcard:country-name\": {\n        \"@value\": \"NL-UT\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:gps\": {\n        \"@value\": \"52.1352365,5.0280565\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:street-address\": {\n        \"@value\": \"Bisonspoor\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:postal-code\": {\n        \"@value\": \"3605LB\",\n        \"@type\": \"xsd:string\"\n      },\n      \"vcard:locality\": {\n        \"@value\": \"Maarssen\",\n        \"@type\": \"xsd:string\"\n      }\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"issuanceDate\": \"2023-02-09T14:55:32.251Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-02-09T14:55:32Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..tYNSjLxt-d8oRF6T0-d0TTKcPqi3hvq9Bbnt1q_svqkCanQAdHEneRIUr4re3aCkwW1slwLrnF_gopcOJKqm9PO0nmQA3p5R9o4V2k9u381DhXzEDVqwS28uwx-fKU9-_7tH0s2KMjmVLs8xz_r9Oju-vFM_lsngfZ4gxsVIG3968MB2LixExVKkfgGWUqTGMx-epLxA2oX0LkT5gKaZHB14n60tT4wXJG-UYDsngJK67iDZgnBT0g-be3GS9gQf1cG1me0Gd9W8rHfACR5RO0d4xkzuwTvIo_kDtnsvvC2VheKZZd4c8B0ONuGE45Wfe-K68Qx3VelDw1Xns5v6nw\"\n  }\n}\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.9.4-unstable.2","_nodeVersion":"16.20.0","_npmVersion":"lerna/6.5.0/node@v16.20.0+x64 (linux)","dist":{"integrity":"sha512-BeRWZDGFZybuYIUNjuTbXuGEWurXRk32XmwDwBTx5ol4Wa/hARbKADHmIfSii6zGeqaBXtyi6uulV0Ic1CJI0Q==","shasum":"33c27f0905cb7bd3f1b69bbca901e4492e50927f","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.9.4-unstable.2.tgz","fileCount":47,"unpackedSize":393450,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDzqn8RSdKGJtCPau0r35MTNT0kFEl5R6y4lEL3G+tPhQIhAP3sARBsipo6BAfSSyLsZLuVUiNo6NoXnl98/1sfghMf"}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.9.4-unstable.2_1685142242027_0.5006609244705771"},"_hasShrinkwrap":false},"0.9.4-unstable.5":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.9.4-unstable.5","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"^0.9.4-unstable.5+23f926a","@sphereon/ssi-sdk-ext.did-utils":"0.12.1-next.2","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk.core":"0.11.1-next.70","@sphereon/ssi-types":"0.11.1-next.70","@sphereon/ssi-sdk-ext.key-manager":"0.12.1-next.2","@sphereon/ssi-sdk-ext.kms-local":"0.12.1-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-ext.did-utils":"0.12.1-next.2","@sphereon/ssi-sdk.vc-handler-ld-local":"0.11.1-next.70","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"23f926a3074de12e7dbca4d7b547ad16c5d9326b","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 18\n\nPlease download NodeJS version 18. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v18.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config            Agent configuration\n  did               Decentralized Identifiers (DID) commands\n  vc                Generic Verifiable Credential commands\n  vp                Generic Verifiable Presentation commands\n  ecosystem         Ecosystem specific commands\n  participant       Participant commands\n  so|service        Service Offering commands\n  export [options]  Exports all agent data so it can be hosted or backed-up\n  help [command]    display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Gaia-X Versions\n\nThere are a couple of gaia-x versions that you can interact with using this library:\n\n- 2206\n\n  _this version is the first version that this tool created to support._\n\n- 2210\n  _this version is supported with a twist. We have changed the CS to accept VerifiablePresentation instead of 2 VerifiableCredentials._\n- 1.2.8 (latest)\n  _this version is the first version that supports VerifiablePresentation by design._\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v1.2.8\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n(specific to versions below v1.2.8)\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -sif ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.9.4-unstable.5","_nodeVersion":"16.20.0","_npmVersion":"lerna/6.5.0/node@v16.20.0+x64 (linux)","dist":{"integrity":"sha512-UH710m5KVxDbN888xsfn9DA9eMMR5EGDMFKOg/F8ovEaBZNkC5yzP6tcSUoFaklV7rNTMQ+yKjWpQYxMi70+Ug==","shasum":"296cd7034829dc6ff952e810db8262d1185d9caf","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.9.4-unstable.5.tgz","fileCount":47,"unpackedSize":404775,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFjKR9FqqUS4D3Z/8aEVk5+JDmZdNUZc7vD84/9LVWn7AiEA3FWc0FqcLoI3sSF6DNNHyCXF8gRehDuwe/8KKDGbNJc="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.9.4-unstable.5_1685942489305_0.04772391148016153"},"_hasShrinkwrap":false},"0.9.4-unstable.6":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.9.4-unstable.6","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"0.9.4-unstable.6+b0bdea1","@sphereon/ssi-sdk-ext.did-utils":"0.12.1-next.2","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk.core":"0.11.1-next.70","@sphereon/ssi-types":"0.11.1-next.70","@sphereon/ssi-sdk-ext.key-manager":"0.12.1-next.2","@sphereon/ssi-sdk-ext.kms-local":"0.12.1-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-ext.did-utils":"0.12.1-next.2","@sphereon/ssi-sdk.vc-handler-ld-local":"0.11.1-next.70","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"b0bdea190d23aa3c418160ea3a1e810095c2bc62","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 18\n\nPlease download NodeJS version 18. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v18.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config            Agent configuration\n  did               Decentralized Identifiers (DID) commands\n  vc                Generic Verifiable Credential commands\n  vp                Generic Verifiable Presentation commands\n  ecosystem         Ecosystem specific commands\n  participant       Participant commands\n  so|service        Service Offering commands\n  export [options]  Exports all agent data so it can be hosted or backed-up\n  help [command]    display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Gaia-X Versions\n\nThere are a couple of gaia-x versions that you can interact with using this library:\n\n- 2206\n\n  _this version is the first version that this tool created to support._\n\n- 2210\n  _this version is supported with a twist. We have changed the CS to accept VerifiablePresentation instead of 2 VerifiableCredentials._\n- 1.2.8 (latest)\n  _this version is the first version that supports VerifiablePresentation by design._\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v1.2.8\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n(specific to versions below v1.2.8)\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -sif ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.9.4-unstable.6","_nodeVersion":"16.20.0","_npmVersion":"lerna/6.5.0/node@v16.20.0+x64 (linux)","dist":{"integrity":"sha512-+QcJOftx93jge0WSyNuPvKxwYpNIwG0iQ9xljty/R0c7MnckgmpqPgvyXLM3FtO8+4s1qOgRegtS8BqbCCoQSA==","shasum":"579f46cea834c912fc96fcc9f3e3355ba1fc326c","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.9.4-unstable.6.tgz","fileCount":47,"unpackedSize":404774,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFXIsdJUJmnydZonkz0zY6DX+AIJm1F7KCjcIs+ch2sgAiEAypp9TwJ9cKTKRglocD+L0SM7cjZs6l66Cd6ja9teu6k="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.9.4-unstable.6_1685943856424_0.018136498603357643"},"_hasShrinkwrap":false},"0.9.4-unstable.8":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.9.4-unstable.8","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"0.9.4-unstable.8+313f8d4","@sphereon/ssi-sdk-ext.did-utils":"0.12.1-next.2","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk.core":"0.11.1-next.70","@sphereon/ssi-types":"0.11.1-next.70","@sphereon/ssi-sdk-ext.key-manager":"0.12.1-next.2","@sphereon/ssi-sdk-ext.kms-local":"0.12.1-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-ext.did-utils":"0.12.1-next.2","@sphereon/ssi-sdk.vc-handler-ld-local":"0.11.1-next.70","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"313f8d47edbf785e5edf2a2a6e2fcb90fc823c4f","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 18\n\nPlease download NodeJS version 18. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v18.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config            Agent configuration\n  did               Decentralized Identifiers (DID) commands\n  vc                Generic Verifiable Credential commands\n  vp                Generic Verifiable Presentation commands\n  ecosystem         Ecosystem specific commands\n  participant       Participant commands\n  so|service        Service Offering commands\n  export [options]  Exports all agent data so it can be hosted or backed-up\n  help [command]    display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Gaia-X Versions\n\nThere are a couple of gaia-x versions that you can interact with using this library:\n\n- 2206\n\n  _this version is the first version that this tool created to support._\n\n- 2210\n  _this version is supported with a twist. We have changed the CS to accept VerifiablePresentation instead of 2 VerifiableCredentials._\n- 1.2.8 (latest)\n  _this version is the first version that supports VerifiablePresentation by design._\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v1.2.8\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n(specific to versions below v1.2.8)\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -sif ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.9.4-unstable.8","_nodeVersion":"16.20.0","_npmVersion":"lerna/6.5.0/node@v16.20.0+x64 (linux)","dist":{"integrity":"sha512-pUiz+u/NFDHI1AZDwKmoJgqMRi9SbdDvDad4Od4xbKiL6GN5agZ9ksB6m7WmxOzUzeGquKJLtjKTx4Ra6/BQLA==","shasum":"cd52083e10ac895c5720b55e459481de1de2eec5","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.9.4-unstable.8.tgz","fileCount":47,"unpackedSize":382950,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIDVWGAW+wf7JUK3udBSTh9XjghFjhTr4+yP32wlZKTVRAiEArglHXyA96Cr8WA+fWXKt2hNDSzp5yECNX+usM2e5Jl8="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.9.4-unstable.8_1686132659240_0.8018120930363781"},"_hasShrinkwrap":false},"0.9.4-unstable.9":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.9.4-unstable.9","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"0.9.4-unstable.9+76a5d92","@sphereon/ssi-sdk-ext.did-utils":"0.12.1-next.2","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk.core":"0.11.1-next.70","@sphereon/ssi-types":"0.11.1-next.70","@sphereon/ssi-sdk-ext.key-manager":"0.12.1-next.2","@sphereon/ssi-sdk-ext.kms-local":"0.12.1-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-ext.did-utils":"0.12.1-next.2","@sphereon/ssi-sdk.vc-handler-ld-local":"0.11.1-next.70","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"76a5d9296f022ff78d549b36dca6a9c407b78410","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 18\n\nPlease download NodeJS version 18. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v18.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config            Agent configuration\n  did               Decentralized Identifiers (DID) commands\n  vc                Generic Verifiable Credential commands\n  vp                Generic Verifiable Presentation commands\n  ecosystem         Ecosystem specific commands\n  participant       Participant commands\n  so|service        Service Offering commands\n  export [options]  Exports all agent data so it can be hosted or backed-up\n  help [command]    display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Gaia-X Versions\n\nThere are a couple of gaia-x versions that you can interact with using this library:\n\n- 2206\n\n  _this version is the first version that this tool created to support._\n\n- 2210\n  _this version is supported with a twist. We have changed the CS to accept VerifiablePresentation instead of 2 VerifiableCredentials._\n- 1.2.8 (latest)\n  _this version is the first version that supports VerifiablePresentation by design._\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v1.2.8\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n(specific to versions below v1.2.8)\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -sif ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.9.4-unstable.9","_nodeVersion":"16.20.0","_npmVersion":"lerna/6.5.0/node@v16.20.0+x64 (linux)","dist":{"integrity":"sha512-O6c/KKVl62/IEZrn52inLp/4EpdSzaorI6U9U/OvfDkZ4wqQtnDcXY1UNcklW0ClA/WgpW04uHMJ9lb43YL3+g==","shasum":"fa9cd679d8f7bdb8d6ca33a8f5423196ad319e23","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.9.4-unstable.9.tgz","fileCount":47,"unpackedSize":382962,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICBSbrqk6oV/M3F5PTUsf557fk8LDSOFiuC0zPNr3sZXAiEA/JvmjMIExVyLQNBX9h/uuDlc5d7PbFZkIZmmUciBMD4="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.9.4-unstable.9_1686209402829_0.9065527261649977"},"_hasShrinkwrap":false},"0.9.4-unstable.10":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.9.4-unstable.10","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"0.9.4-unstable.10+a20d1ea","@sphereon/ssi-sdk-ext.did-utils":"0.12.1-next.2","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk.core":"0.11.1-next.70","@sphereon/ssi-types":"0.11.1-next.70","@sphereon/ssi-sdk-ext.key-manager":"0.12.1-next.2","@sphereon/ssi-sdk-ext.kms-local":"0.12.1-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-ext.did-utils":"0.12.1-next.2","@sphereon/ssi-sdk.vc-handler-ld-local":"0.11.1-next.70","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"a20d1ea05c707c2369fedb25efb2836317a47602","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 18\n\nPlease download NodeJS version 18. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v18.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config            Agent configuration\n  did               Decentralized Identifiers (DID) commands\n  vc                Generic Verifiable Credential commands\n  vp                Generic Verifiable Presentation commands\n  ecosystem         Ecosystem specific commands\n  participant       Participant commands\n  so|service        Service Offering commands\n  export [options]  Exports all agent data so it can be hosted or backed-up\n  help [command]    display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Gaia-X Versions\n\nThere are a couple of gaia-x versions that you can interact with using this library:\n\n- 2206\n\n  _this version is the first version that this tool created to support._\n\n- 2210\n  _this version is supported with a twist. We have changed the CS to accept VerifiablePresentation instead of 2 VerifiableCredentials._\n- 1.2.8 (latest)\n  _this version is the first version that supports VerifiablePresentation by design._\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v1.2.8\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n(specific to versions below v1.2.8)\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -sif ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.9.4-unstable.10","_nodeVersion":"16.20.0","_npmVersion":"lerna/6.5.0/node@v16.20.0+x64 (linux)","dist":{"integrity":"sha512-B7mDYDACx0mCPinX3iryZ4O5pT6LOsLbyztNPXTDptQ+jwnVhGrZF+inL1+4gnbDqDvu4esmgJFfDJRYQPDz2w==","shasum":"3d5381ae00940f6b1d14ac1178779a2a2d3e084f","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.9.4-unstable.10.tgz","fileCount":47,"unpackedSize":383992,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC3zaUoOhcsQ1/NYKNWvb7JKChbHTUZKLag+yT6cN3mpQIgIq9hUF8hVcWmE+KeHCrZ4qpj6o4PR1IN3WgyToxMZIk="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.9.4-unstable.10_1686220601726_0.03740398006059342"},"_hasShrinkwrap":false},"0.9.4-unstable.11":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.9.4-unstable.11","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"0.9.4-unstable.11+fb3c548","@sphereon/ssi-sdk-ext.did-utils":"0.12.1-next.2","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk.core":"0.11.1-next.70","@sphereon/ssi-types":"0.11.1-next.70","@sphereon/ssi-sdk-ext.key-manager":"0.12.1-next.2","@sphereon/ssi-sdk-ext.kms-local":"0.12.1-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-ext.did-utils":"0.12.1-next.2","@sphereon/ssi-sdk.vc-handler-ld-local":"0.11.1-next.70","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"fb3c548643094382746d1a07436e7adcc540cae4","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 18\n\nPlease download NodeJS version 18. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v18.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config            Agent configuration\n  did               Decentralized Identifiers (DID) commands\n  vc                Generic Verifiable Credential commands\n  vp                Generic Verifiable Presentation commands\n  ecosystem         Ecosystem specific commands\n  participant       Participant commands\n  so|service        Service Offering commands\n  export [options]  Exports all agent data so it can be hosted or backed-up\n  help [command]    display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Gaia-X Versions\n\nThere are a couple of gaia-x versions that you can interact with using this library:\n\n- 2206\n\n  _this version is the first version that this tool created to support._\n\n- 2210\n  _this version is supported with a twist. We have changed the CS to accept VerifiablePresentation instead of 2 VerifiableCredentials._\n- 1.2.8 (latest)\n  _this version is the first version that supports VerifiablePresentation by design._\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v1.2.8\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n(specific to versions below v1.2.8)\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -sif ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.9.4-unstable.11","_nodeVersion":"16.20.0","_npmVersion":"lerna/6.5.0/node@v16.20.0+x64 (linux)","dist":{"integrity":"sha512-fF5yuogvZwarTYglQ1UYdWDgdtpzxVQ0Jna6FEvCLDRObVRLAsonN7/3wNINwlnoh8kowTt1wf/bHdQ7ChJoGg==","shasum":"f5877f9d28eb4bf6fc5bf02e784927095449f1cb","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.9.4-unstable.11.tgz","fileCount":47,"unpackedSize":383813,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIBeEv/wH7PHIxlTGfzsA824eolsn6eVbvWrU8l5qIBhNAiEAxF2H4e1zV76UBcpKf4hO1lbjw0FGEO/iqQJOEfIqzG8="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.9.4-unstable.11_1686220723242_0.20554537070684709"},"_hasShrinkwrap":false},"0.9.4-unstable.12":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.9.4-unstable.12","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"0.9.4-unstable.12+bd49789","@sphereon/ssi-sdk-ext.did-utils":"0.12.1-next.2","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk.core":"0.11.1-next.70","@sphereon/ssi-types":"0.11.1-next.70","@sphereon/ssi-sdk-ext.key-manager":"0.12.1-next.2","@sphereon/ssi-sdk-ext.kms-local":"0.12.1-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-ext.did-utils":"0.12.1-next.2","@sphereon/ssi-sdk.vc-handler-ld-local":"0.11.1-next.70","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"bd497894cd640de0e8155a400bc8a680bbaffb86","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 18\n\nPlease download NodeJS version 18. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v18.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config            Agent configuration\n  did               Decentralized Identifiers (DID) commands\n  vc                Generic Verifiable Credential commands\n  vp                Generic Verifiable Presentation commands\n  ecosystem         Ecosystem specific commands\n  participant       Participant commands\n  so|service        Service Offering commands\n  export [options]  Exports all agent data so it can be hosted or backed-up\n  help [command]    display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Gaia-X Versions\n\nThere are a couple of gaia-x versions that you can interact with using this library:\n\n- 2206\n\n  _this version is the first version that this tool created to support._\n\n- 2210\n  _this version is supported with a twist. We have changed the CS to accept VerifiablePresentation instead of 2 VerifiableCredentials._\n- 1.2.8 (latest)\n  _this version is the first version that supports VerifiablePresentation by design._\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v1.2.8\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n(specific to versions below v1.2.8)\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -sif ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.9.4-unstable.12","_nodeVersion":"16.20.0","_npmVersion":"lerna/6.5.0/node@v16.20.0+x64 (linux)","dist":{"integrity":"sha512-Q5MW+FUNn4mzI8/zYMJjElKwF45sVX6rZfue8NvoR6ReEzm4KRzAmEe80I0wT37Wz03XdbX4ydmiIVJ/k6ijzA==","shasum":"f7d9ea7e24463c9b567e9337ee1428d90cf4fdae","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.9.4-unstable.12.tgz","fileCount":47,"unpackedSize":383829,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIFWuon2riBpC/BEyaB06Ux+A1yBKOlnqJxu294s4XEnSAiEAosmHoEw+ZfjF0vQ+c38GOJGTeaKDTRRfQH39Gu7sltg="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.9.4-unstable.12_1686223672204_0.49512241175014404"},"_hasShrinkwrap":false},"0.9.4-unstable.13":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.9.4-unstable.13","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"0.9.4-unstable.13+709071f","@sphereon/ssi-sdk-ext.did-utils":"0.12.1-next.2","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk.core":"0.11.1-next.70","@sphereon/ssi-types":"0.11.1-next.70","@sphereon/ssi-sdk-ext.key-manager":"0.12.1-next.2","@sphereon/ssi-sdk-ext.kms-local":"0.12.1-next.2","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-ext.did-utils":"0.12.1-next.2","@sphereon/ssi-sdk.vc-handler-ld-local":"0.11.1-next.70","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"709071f158296d5aa0e4340abe6020e3d4bdafc1","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Prerequisites and installation\n\n## NodeJS version 18\n\nPlease download NodeJS version 18. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v18.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config            Agent configuration\n  did               Decentralized Identifiers (DID) commands\n  vc                Generic Verifiable Credential commands\n  vp                Generic Verifiable Presentation commands\n  ecosystem         Ecosystem specific commands\n  participant       Participant commands\n  so|service        Service Offering commands\n  export [options]  Exports all agent data so it can be hosted or backed-up\n  help [command]    display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Gaia-X Versions\n\nThere are a couple of gaia-x versions that you can interact with using this library:\n\n- 2206\n\n  _this version is the first version that this tool created to support._\n\n- 2210\n  _this version is supported with a twist. We have changed the CS to accept VerifiablePresentation instead of 2 VerifiableCredentials._\n- 1.2.8 (latest)\n  _this version is the first version that supports VerifiablePresentation by design._\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v1.2.8\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the registration numbers:\nIf you do not have a certain registration number, remove the part between the `{ }` brackets. For instance If you do not\nhave LEI code, you should remove the next part altogether:\n(specific to versions below v1.2.8)\n\n```json\n{\n  \"gx-participant:registrationNumberType\": \"leiCode\",\n  \"gx-participant:registrationNumberNumber\": \"9695007586GCAKPYJ703\"\n},\n```\n\nMake sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it\nwill always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -sif ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent compliance sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ ParticipantCredential │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:05:00.166Z │ d7ae24cbb223adb0df025548a691b684e995843fe6b9f549a9c517167ba68bd26545d759bae5dfe192598e86b7a6ef6874fb9a8c3859fd8317ed379ec9c6414b │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 816826d6-8e1f-4cc6-89a6-a77ae4b63771 │ 2023-01-26T03:04:58.179Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:164e-2001-1c04-2b10-ee00-e375-2d7a-ffc3-9904.ngrok-free.app#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The particpant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering\nself-description. This is a so called Credential. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n├────────────────────────────────┤\n│ AutoscaledVirtualMachine       │\n├────────────────────────────────┤\n│ ComputeFunction                │\n├────────────────────────────────┤\n│IdentityAccessManagementOffering│\n├────────────────────────────────┤\n│ VirtualMachine                 │\n├────────────────────────────────┤\n│ InstantiatedVirtualResource    │\n├────────────────────────────────┤\n│ VerifiableCredentialWallet     │\n├────────────────────────────────┤\n│ PlatformOffering               │\n├────────────────────────────────┤\n│ Location                       │\n├────────────────────────────────┤\n│ ObjectStorageOffering          │\n├────────────────────────────────┤\n│ BigData                        │\n├────────────────────────────────┤\n│ InfrastructureOffering         │\n├────────────────────────────────┤\n│ Connectivity                   │\n├────────────────────────────────┤\n│ ServiceOffering                │\n├────────────────────────────────┤\n│ Database                       │\n├────────────────────────────────┤\n│ WalletOffering                 │\n├────────────────────────────────┤\n│ ImageRegistryOffering          │\n├────────────────────────────────┤\n│ IdentityFederation             │\n├────────────────────────────────┤\n│ SoftwareOffering               │\n├────────────────────────────────┤\n│ LinkConnectivity               │\n├────────────────────────────────┤\n│ PhysicalConnectivity           │\n├────────────────────────────────┤\n│ Container                      │\n├────────────────────────────────┤\n│ Interconnection                │\n├────────────────────────────────┤\n│ StorageOffering                │\n├────────────────────────────────┤\n│ AutoscaledContainer            │\n├────────────────────────────────┤\n│ Catalogue                      │\n├────────────────────────────────┤\n│ Compute                        │\n├────────────────────────────────┤\n│ NetworkOffering                │\n├────────────────────────────────┤\n│ NetworkConnectivity            │\n├────────────────────────────────┤\n│ LocatedServiceOffering         │\n├────────────────────────────────┤\n│ BareMetal                      │\n├────────────────────────────────┤\n│ FileStorageOffering            │\n├────────────────────────────────┤\n│ IdentityProvider               │\n├────────────────────────────────┤\n│ Orchestration                  │\n├────────────────────────────────┤\n│ BlockStorageOffering           │\n├────────────────────────────────┤\n│ DigitalIdentityWallet          │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent so  so sd export-example -t IdentityAccessManagementOffering\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│             type │                                sd-file │                                                              did │\n├──────────────────┼────────────────────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io │\n└──────────────────┴────────────────────────────────────────┴──────────────────────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\"\n  ],\n  \"issuer\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n  \"id\": \"381d1f99-173d-4be3-9043-7e53cee0f9ae\",\n  \"credentialSubject\": {\n    \"@context\": {\n      \"cc\": \"http://creativecommons.org/ns#\",\n      \"schema\": \"http://schema.org/\",\n      \"cred\": \"https://www.w3.org/2018/credentials#\",\n      \"void\": \"http://rdfs.org/ns/void#\",\n      \"owl\": \"http://www.w3.org/2002/07/owl#\",\n      \"xsd\": \"http://www.w3.org/2001/XMLSchema#\",\n      \"gax-validation\": \"http://w3id.org/gaia-x/validation#\",\n      \"skos\": \"http://www.w3.org/2004/02/skos/core#\",\n      \"voaf\": \"http://purl.org/vocommons/voaf#\",\n      \"rdfs\": \"http://www.w3.org/2000/01/rdf-schema#\",\n      \"vcard\": \"http://www.w3.org/2006/vcard/ns#\",\n      \"gax-core\": \"http://w3id.org/gaia-x/core#\",\n      \"dct\": \"http://purl.org/dc/terms/\",\n      \"sh\": \"http://www.w3.org/ns/shacl#\",\n      \"gax-trust-framework\": \"http://w3id.org/gaia-x/gax-trust-framework#\",\n      \"rdf\": \"http://www.w3.org/1999/02/22-rdf-syntax-ns#\",\n      \"ids\": \"https://w3id.org/idsa/core/\",\n      \"dcat\": \"http://www.w3.org/ns/dcat#\",\n      \"vann\": \"http://purl.org/vocab/vann/\",\n      \"foaf\": \"http://xmlns.com/foaf/0.1/\",\n      \"did\": \"https://www.w3.org/TR/did-core/#\"\n    },\n    \"id\": \"did:web:b7fd-2001-1c04-2b10-ee00-c85d-ad93-ccd9-1b0d.eu.ngrok.io\",\n    \"@type\": \"gax-trust-framework:IdentityAccessManagementOffering\"\n  },\n  \"type\": [\n    \"VerifiableCredential\"\n  ]\n}\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `-s/--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\n\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent so sd submit -soi <ID of a signed ServiceOffering self-description stored>  -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance>\n\nOuput:\n┌──────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│ verifiableCredential │                                                                                                                             hash │\n├──────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│      [object Object] │ 5b55d322eb2bda3899c94ba6617aca2376314a02d59700a1c68d5dbee19aa640ba5576a57bdbd03a356dfa71735423e9ae4da09a2e3df05c1d6dd8c6f9a292f0 │\n└──────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a ServiceOffering Credential, which is issued by the compliance server\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌───────────────────────────────────────┬─────────────────────────┬─────────────────────────┬──────────────────────────┬───────────────────────────────┐\n│                                 types │                  issuer │                subject  │           issuance-date  │                           id  │\n├───────────────────────────────────────┼─────────────────────────┼─────────────────────────┼──────────────────────────┼───────────────────────────────┤\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:55:49.789Z │ <participant sd id>           │\n│                 ParticipantCredential │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:55:51.753Z │ <participant compliance id>   │\n│                  VerifiableCredential │ did:web:participant_url │ did:web:participant_url │ 2023-03-02T09:57:16.484Z │ <so sd id>                    │\n│ ServiceOfferingCredentialExperimental │ did:web:compliance url  │ did:web:participant_url │ 2023-03-02T09:57:18.527Z │ <so compliance id>            │\n└───────────────────────────────────────┴─────────────────────────┴─────────────────────────┴──────────────────────────┴───────────────────────────────┘\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `-s/--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.9.4-unstable.13","_nodeVersion":"16.20.0","_npmVersion":"lerna/6.5.0/node@v16.20.0+x64 (linux)","dist":{"integrity":"sha512-ojX4oGllNnz8GFqMoPnHvOWNocYtcAxH9KtFe0vkApS3qP58/iUZq2t8EsstYzasQAw28UIjh00YCVKYDi7+nA==","shasum":"4bc45731eb16891f52794161aec3d4d6e9d9b633","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.9.4-unstable.13.tgz","fileCount":47,"unpackedSize":383829,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIFUWUMJf5k5zNMpyTkYqePf+trc3X86A50yAgIoD2BcKAiBze7AQfNqlNVEsf4CGf3YCG/IMl48wVCnivCZBbafhOQ=="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.9.4-unstable.13_1686226088306_0.20194586436552897"},"_hasShrinkwrap":false},"0.9.5-next.16":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.9.5-next.16","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"0.9.5-next.16+ab4500a","@sphereon/ssi-sdk-ext.did-utils":"0.12.2-next.3","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk.core":"0.13.0","@sphereon/ssi-types":"0.13.0","@sphereon/ssi-sdk-ext.key-manager":"0.12.2-next.3","@sphereon/ssi-sdk-ext.kms-local":"0.12.2-next.3","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-ext.did-utils":"0.12.2-next.3","@sphereon/ssi-sdk.vc-handler-ld-local":"0.13.0","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"ab4500a59bd5013f67e07af0f04f4d0dbf9bfe43","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Overview\n\nAfter Prerequisites and installation part, we will discuss how to setup your own X.509 keys and SSL certificate. What follows is a guide for using this cli agent to connect to a gaia-x compatible Compliance Service (gx-compliance for short).\nBelow you can see a simple workflow scenario of this CLI tool:\n\n![Flow diagram](https://github.com/Sphereon-Opensource/gx-agent/blob/develop/docs/simple-gx-flow.puml)\n\n# Prerequisites and installation\n\n## NodeJS version 18\n\nPlease download NodeJS version 18. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v18.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config            Agent configuration\n  did               Decentralized Identifiers (DID) commands\n  vc                Generic Verifiable Credential commands\n  vp                Generic Verifiable Presentation commands\n  ecosystem         Ecosystem specific commands\n  participant       Participant commands\n  so|service        Service Offering commands\n  export [options]  Exports all agent data so it can be hosted or backed-up\n  help [command]    display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Gaia-X Versions\n\nThere has been a couple of gaia-x versions, since there are major changes between versions, this library intends to only support the latest **v1.2.8**\n_support for versions v2206 and v2210 are removed in this release_\n\n- 1.2.8 (latest)\n  _this version is the first version that supports VerifiablePresentation by design._\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v1.2.8\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the keys that are mentioned in the context file:\n\n- gx:legalRegistrationNumber\n- gx:parentOrganization\n- gx:subOrganization\n- gx:headquarterAddress\n- gx:legalAddress\n  For a better guide on how to populate your requested field you can take a look at the main shape file: https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\n\n- Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it will always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -sif ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent participant sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ Compliance            │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T14:21:10.896Z │ 763640a06a6c65f79c79d0ff7e549ba1241e06ff260fb98103e67afbc818fe0b82371c2e63907c63a938b836f7dfe85055e8ece07051226516b2143320e020ce │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io      │ 2023-05-29T18:03:00.887Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"2023-05-29T18:03:00.887Z\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `---show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ verified │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The participant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering self-description. This is a so called \"Credential\". You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\nIn the current version you can create an example with calling agent:\n\n_The ServiceOffering and it's example might change in the near future as GAIA-X team are modifying this part_\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ gx_ServiceOffering             │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\n\ngx-agent so sd example -d\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬────────────────────────────────────────────────┐\n│             type │                                sd-file │                                            did │\n├──────────────────┼────────────────────────────────────────┼────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io                │\n└──────────────────┴────────────────────────────────────────┴────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"urn:uuid:b0aee1c5-a00f-46b4-8142-dbe60903f8b2\",\n  \"credentialSubject\": {\n    \"id\": \"https://nk-gx-agent.eu.ngrok.io\",\n    \"type\": \"gx:ServiceOffering\",\n    \"gx:providedBy\": {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\"\n    },\n    \"gx:policy\": \"\",\n    \"gx:termsAndConditions\": {\n      \"gx:URL\": \"http://termsandconds.com\",\n      \"gx:hash\": \"d8402a23de560f5ab34b22d1a142feb9e13b3143\"\n    },\n    \"gx:dataAccountExport\": {\n      \"gx:requestType\": \"API\",\n      \"gx:accessType\": \"digital\",\n      \"gx:formatType\": \"application/json\"\n    }\n  },\n  \"type\": \"VerifiableCredential\"\n}\n\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the ServiceOffering self-description input file. It sends that in\nas a Verifiable Presentation with previously fetched ComplianceCredential and Participant SelfDescription to the Ecosystem Compliance service as configured in your agent.yml file.\n\n```json\n{\n  \"type\": [\"VerifiablePresentation\"],\n  \"@context\": [\"https://www.w3.org/2018/credentials/v1\"],\n  \"verifiableCredential\": [\n    { // Your LegalParticipant self-description VerifiableCredential },\n    { // Your ServiceOffering self-description  VerifiableCredential },\n    { // Your LegalParticipant Compliance Credential Signed by Gaia-X Compliance service },\n  ],\n  \"holder\": \"did:web:4c30-2001-1c04-2b10-ee00-e7d5-abed-7e72-9d92.ngrok-free.app\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-06-01T08:47:10Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..h-rEB7ZPqRCh4Pb9eXK7iX4PEtwF9GdHlrrMR6JSnybVMsxnKcN5tBgqJx33dSIXyPtPSciA2rcp2d7qyQ_tr60oD2dMwu2xnYqgRL67iIkGfg8jIRpunjrZG2PQXPK61ziZvGo4HwuVztY5bwZAqtGTKRs7dWona3U7q2uGsELHojFoHIHfR_j0RPSxLWh8ek_8ZNE13aNVR9QvPwUcxEJ9OGhifhO6XVwwFUDtNtgbGqIU4mwdSC6DU2h6yUsYSK2pu7SRj7qrq4cDbp70OAuLwV8Sywg5IqxuJKKlJZq5YJy_7hgBSvr3RcqeY8BSFr7-H2QGg2n9HuWRIKuwNg\"\n  }\n}\n```\n\nAnd you Ecosystem Compliance Service will send you another ComplianceCredential in response:\n\n```json\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu//development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\"VerifiableCredential\"],\n  \"id\": \"https://nk-eco-compliance.eu.ngrok.io/credential-offers/67645d91-6bb5-4661-a6d1-2d36dce30172\",\n  \"issuer\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n  \"issuanceDate\": \"2023-05-31T14:10:01.794Z\",\n  \"expirationDate\": \"2023-08-29T14:10:01.794Z\",\n  \"credentialSubject\": [\n    {\n      \"type\": \"gx:compliance\",\n      \"id\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n      \"integrity\": \"sha256-d03feb54fedcb3ed0411f723bdd8b19e928d742a49f4c7ca109979e08ac83974\"\n    },\n    {\n      \"type\": \"gx:compliance\",\n      \"id\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n      \"integrity\": \"sha256-198332fad39100e726dcc94bd1c68dfbee2db02befc12c92e35e7648b4399336\"\n    },\n    {\n      \"type\": \"gx:compliance\",\n      \"id\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n      \"integrity\": \"sha256-11fb3ded1ce29b06c5ad15f2bcc8bf1eac41973e70289bf41600aeb1dffe5356\"\n    }\n  ],\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-31T14:10:02.314Z\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..AbRrpo2qbgaCS6HAykU6PACi37iFxlviyu2hxrfhhjhvmz7sItIPFMQc_fj-qGyXD6Zr_LoA2aR5kFE2w4zgu0oEP8Mmudf4fTKzl-3vPNY9lfEUf9tLg_LxLzivs24C2Vz4y2--r2BkNeeXTJ7_pnlBWuDoVPNm3gcrfcT69VcLWmZpErOqhbHTmqafoklr4iGOs7ehU9TGxXS7JptGglAZ_caBVfHvIQQi1MP31mQeIJk7U_t7KohW4Y5ZQKjBL36OL2OqPprZhBEcouOGqI82fRKxAdq22AIjFkgarg9QavwLlq1F_F0qxshpR_QGBE55LV9uU6NJ877Is2sa_w\",\n    \"verificationMethod\": \"did:web:nk-eco-compliance.eu.ngrok.io#JWK2020-RSA\"\n  }\n}\n```\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌─────────────────────┬───────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│               types │                                issuer │                         subject │            issuance-date │                                                               id │\n├─────────────────────┼───────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ gx:LegalParticipant │ did:web:nk-gx-agent.eu.ngrok.io       │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T13:08:29.888Z │ <participant sd id>                                              │\n│ ServiceOffering     │ did:web:nk-gx-agent.eu.ngrok.io       │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T13:08:29.888Z │ <service offering sd id>                                         │\n│          Compliance │ did:web:nk-gx-compliance.eu.ngrok.io  │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T14:10:52.037Z │ <participant compliance id from gx-compliance>                   │\n│          Compliance │ did:web:nk-eco-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T14:26:49.870Z │ <participant and service offering compliance from eco-compliance>│\n└─────────────────────┴───────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────┘\n\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.9.5-next.16","_nodeVersion":"16.20.1","_npmVersion":"lerna/6.5.0/node@v16.20.1+x64 (linux)","dist":{"integrity":"sha512-1p4UxZtrpufSZ+LC+zOSttJhUcxJtO1/GZDNJcGyxA2Hz3BNYgzXVzNNv/2h+mzCNFIGaO+PHjxHmeFOWsRVSA==","shasum":"5a7104868f2ba0366be6efe8ff458f112db3aac0","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.9.5-next.16.tgz","fileCount":47,"unpackedSize":379941,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIGxCXVmjgo2ghKbTwyHVe32DjtriFMJOl1g7QMUzIHzkAiEAjkxSc9fewXWQ0EVShkPXj/ig4vdI+Cbg6TuwiybPiBA="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.9.5-next.16_1689025725889_0.5486825623632468"},"_hasShrinkwrap":false},"0.10.0":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.10.0","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"0.10.0","@sphereon/ssi-sdk-ext.did-utils":"0.12.2-next.3","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk.core":"0.13.0","@sphereon/ssi-types":"0.13.0","@sphereon/ssi-sdk-ext.key-manager":"0.12.2-next.3","@sphereon/ssi-sdk-ext.kms-local":"0.12.2-next.3","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-ext.did-utils":"0.12.2-next.3","@sphereon/ssi-sdk.vc-handler-ld-local":"0.13.0","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"cdfbb444b8aa853a72721707074eceb2ee4ddb32","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.10.0","_nodeVersion":"16.20.1","_npmVersion":"lerna/6.5.0/node@v16.20.1+x64 (linux)","dist":{"integrity":"sha512-+Rj6lUDSX/L2gImLvnjzOa+m5aO8NCF6at6P6kdvREaNJSZRWGQULIhdD1PE/ear4WzQlFtwTQm1Lp8F7UU+wQ==","shasum":"7a1af682916aa734c844e943bae944cffbe7cab3","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.10.0.tgz","fileCount":47,"unpackedSize":379911,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEQCIADhW6r+weovo+rcYDW8jf0W2QaclK8M0SAE+6dq3DVcAiAapT83/eO/Umj25/sm9AjR36EH8kPGEUVcQSvBxgfXCg=="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.10.0_1689026268884_0.7366593425019976"},"_hasShrinkwrap":false},"0.10.1-next.1":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.10.1-next.1","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"0.10.1-next.1+c08943d","@sphereon/ssi-sdk-ext.did-utils":"0.12.2-next.3","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk.core":"0.13.0","@sphereon/ssi-types":"0.13.0","@sphereon/ssi-sdk-ext.key-manager":"0.12.2-next.3","@sphereon/ssi-sdk-ext.kms-local":"0.12.2-next.3","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-ext.did-utils":"0.12.2-next.3","@sphereon/ssi-sdk.vc-handler-ld-local":"0.13.0","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"c08943deec68f10551d057ed97b527b04ae64122","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Overview\n\nAfter Prerequisites and installation part, we will discuss how to setup your own X.509 keys and SSL certificate. What follows is a guide for using this cli agent to connect to a gaia-x compatible Compliance Service (gx-compliance for short).\nBelow you can see a simple workflow scenario of this CLI tool:\n\n![Flow diagram](https://github.com/Sphereon-Opensource/gx-agent/blob/develop/docs/simple-gx-flow.puml)\n\n# Prerequisites and installation\n\n## NodeJS version 18\n\nPlease download NodeJS version 18. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v18.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config            Agent configuration\n  did               Decentralized Identifiers (DID) commands\n  vc                Generic Verifiable Credential commands\n  vp                Generic Verifiable Presentation commands\n  ecosystem         Ecosystem specific commands\n  participant       Participant commands\n  so|service        Service Offering commands\n  export [options]  Exports all agent data so it can be hosted or backed-up\n  help [command]    display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to setup a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Gaia-X Versions\n\nThere has been a couple of gaia-x versions, since there are major changes between versions, this library intends to only support the latest **v1.2.8**\n_support for versions v2206 and v2210 are removed in this release_\n\n- 1.2.8 (latest)\n  _this version is the first version that supports VerifiablePresentation by design._\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used in stead. The `--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v1.2.8\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for it's commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by it’s DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Pariticipant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd export-example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for the some of the keys that are mentioned in the context file:\n\n- gx:legalRegistrationNumber\n- gx:parentOrganization\n- gx:subOrganization\n- gx:headquarterAddress\n- gx:legalAddress\n  For a better guide on how to populate your requested field you can take a look at the main shape file: https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\n\n- Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it will always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -sif ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent participant sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ Compliance            │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T14:21:10.896Z │ 763640a06a6c65f79c79d0ff7e549ba1241e06ff260fb98103e67afbc818fe0b82371c2e63907c63a938b836f7dfe85055e8ece07051226516b2143320e020ce │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io      │ 2023-05-29T18:03:00.887Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"2023-05-29T18:03:00.887Z\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `---show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ verified │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The participant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering self-description. This is a so called \"Credential\". You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\nIn the current version you can create an example with calling agent:\n\n_The ServiceOffering and it's example might change in the near future as GAIA-X team are modifying this part_\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ gx_ServiceOffering             │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\n\ngx-agent so sd example -d\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬────────────────────────────────────────────────┐\n│             type │                                sd-file │                                            did │\n├──────────────────┼────────────────────────────────────────┼────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io                │\n└──────────────────┴────────────────────────────────────────┴────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"urn:uuid:b0aee1c5-a00f-46b4-8142-dbe60903f8b2\",\n  \"credentialSubject\": {\n    \"id\": \"https://nk-gx-agent.eu.ngrok.io\",\n    \"type\": \"gx:ServiceOffering\",\n    \"gx:providedBy\": {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\"\n    },\n    \"gx:policy\": \"\",\n    \"gx:termsAndConditions\": {\n      \"gx:URL\": \"http://termsandconds.com\",\n      \"gx:hash\": \"d8402a23de560f5ab34b22d1a142feb9e13b3143\"\n    },\n    \"gx:dataAccountExport\": {\n      \"gx:requestType\": \"API\",\n      \"gx:accessType\": \"digital\",\n      \"gx:formatType\": \"application/json\"\n    }\n  },\n  \"type\": \"VerifiableCredential\"\n}\n\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the ServiceOffering self-description input file. It sends that in\nas a Verifiable Presentation with previously fetched ComplianceCredential and Participant SelfDescription to the Ecosystem Compliance service as configured in your agent.yml file.\n\n```json\n{\n  \"type\": [\"VerifiablePresentation\"],\n  \"@context\": [\"https://www.w3.org/2018/credentials/v1\"],\n  \"verifiableCredential\": [\n    { // Your LegalParticipant self-description VerifiableCredential },\n    { // Your ServiceOffering self-description  VerifiableCredential },\n    { // Your LegalParticipant Compliance Credential Signed by Gaia-X Compliance service },\n  ],\n  \"holder\": \"did:web:4c30-2001-1c04-2b10-ee00-e7d5-abed-7e72-9d92.ngrok-free.app\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-06-01T08:47:10Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..h-rEB7ZPqRCh4Pb9eXK7iX4PEtwF9GdHlrrMR6JSnybVMsxnKcN5tBgqJx33dSIXyPtPSciA2rcp2d7qyQ_tr60oD2dMwu2xnYqgRL67iIkGfg8jIRpunjrZG2PQXPK61ziZvGo4HwuVztY5bwZAqtGTKRs7dWona3U7q2uGsELHojFoHIHfR_j0RPSxLWh8ek_8ZNE13aNVR9QvPwUcxEJ9OGhifhO6XVwwFUDtNtgbGqIU4mwdSC6DU2h6yUsYSK2pu7SRj7qrq4cDbp70OAuLwV8Sywg5IqxuJKKlJZq5YJy_7hgBSvr3RcqeY8BSFr7-H2QGg2n9HuWRIKuwNg\"\n  }\n}\n```\n\nAnd you Ecosystem Compliance Service will send you another ComplianceCredential in response:\n\n```json\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu//development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\"VerifiableCredential\"],\n  \"id\": \"https://nk-eco-compliance.eu.ngrok.io/credential-offers/67645d91-6bb5-4661-a6d1-2d36dce30172\",\n  \"issuer\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n  \"issuanceDate\": \"2023-05-31T14:10:01.794Z\",\n  \"expirationDate\": \"2023-08-29T14:10:01.794Z\",\n  \"credentialSubject\": [\n    {\n      \"type\": \"gx:compliance\",\n      \"id\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n      \"integrity\": \"sha256-d03feb54fedcb3ed0411f723bdd8b19e928d742a49f4c7ca109979e08ac83974\"\n    },\n    {\n      \"type\": \"gx:compliance\",\n      \"id\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n      \"integrity\": \"sha256-198332fad39100e726dcc94bd1c68dfbee2db02befc12c92e35e7648b4399336\"\n    },\n    {\n      \"type\": \"gx:compliance\",\n      \"id\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n      \"integrity\": \"sha256-11fb3ded1ce29b06c5ad15f2bcc8bf1eac41973e70289bf41600aeb1dffe5356\"\n    }\n  ],\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-31T14:10:02.314Z\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..AbRrpo2qbgaCS6HAykU6PACi37iFxlviyu2hxrfhhjhvmz7sItIPFMQc_fj-qGyXD6Zr_LoA2aR5kFE2w4zgu0oEP8Mmudf4fTKzl-3vPNY9lfEUf9tLg_LxLzivs24C2Vz4y2--r2BkNeeXTJ7_pnlBWuDoVPNm3gcrfcT69VcLWmZpErOqhbHTmqafoklr4iGOs7ehU9TGxXS7JptGglAZ_caBVfHvIQQi1MP31mQeIJk7U_t7KohW4Y5ZQKjBL36OL2OqPprZhBEcouOGqI82fRKxAdq22AIjFkgarg9QavwLlq1F_F0qxshpR_QGBE55LV9uU6NJ877Is2sa_w\",\n    \"verificationMethod\": \"did:web:nk-eco-compliance.eu.ngrok.io#JWK2020-RSA\"\n  }\n}\n```\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌─────────────────────┬───────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│               types │                                issuer │                         subject │            issuance-date │                                                               id │\n├─────────────────────┼───────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ gx:LegalParticipant │ did:web:nk-gx-agent.eu.ngrok.io       │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T13:08:29.888Z │ <participant sd id>                                              │\n│ ServiceOffering     │ did:web:nk-gx-agent.eu.ngrok.io       │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T13:08:29.888Z │ <service offering sd id>                                         │\n│          Compliance │ did:web:nk-gx-compliance.eu.ngrok.io  │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T14:10:52.037Z │ <participant compliance id from gx-compliance>                   │\n│          Compliance │ did:web:nk-eco-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T14:26:49.870Z │ <participant and service offering compliance from eco-compliance>│\n└─────────────────────┴───────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────┘\n\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.10.1-next.1","_nodeVersion":"16.20.1","_npmVersion":"lerna/6.5.0/node@v16.20.1+x64 (linux)","dist":{"integrity":"sha512-BcGEApsuvox4MpQLozgj0xXaxzITs4X2S/L4Ibb1FEHErHE3bMPpRmaBQcMWUCrlrreIC6+k+XMBqp6+bJ5joA==","shasum":"d03a7d6e3466a0580b3fe0f24da0d8e3a788afeb","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.10.1-next.1.tgz","fileCount":47,"unpackedSize":379899,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQCRCZ4ZoAV23oXwK7PZ5bL3w9CCEkscFWuWKKxJ+/fEEgIgR3TLI7MjgBqEI80faywgVYrNq+eyPft6PbVJV6WtlrA="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.10.1-next.1_1689060317991_0.26548562871607406"},"_hasShrinkwrap":false},"0.10.1":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.10.1","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"0.10.0","@sphereon/ssi-sdk-ext.did-utils":"0.12.2-next.3","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk.core":"0.13.0","@sphereon/ssi-types":"0.13.0","@sphereon/ssi-sdk-ext.key-manager":"0.12.2-next.3","@sphereon/ssi-sdk-ext.kms-local":"0.12.2-next.3","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-ext.did-utils":"0.12.2-next.3","@sphereon/ssi-sdk.vc-handler-ld-local":"0.13.0","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"26a0d89d9fa29f0da09c9eefee7a1442a87a11b0","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.10.1","_nodeVersion":"16.20.1","_npmVersion":"lerna/6.5.0/node@v16.20.1+x64 (linux)","dist":{"integrity":"sha512-ImqtUBfaAuFVzACdfjUe0BU6m7Hp4mAJhBXlC5evi15pT70z3MSt+w5wD7j0HNSTpwkVa+PDd1+Tl7Ts4W0BGw==","shasum":"04d7eb7c1bbeecb4fc9f590481e6a226e1b0c164","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.10.1.tgz","fileCount":47,"unpackedSize":379869,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCICO2jEc6K6q8Fjq+7EMjodIIMMDJfs6u6/hw8f15lKVTAiEAsplB8Yrdd+RDUsi0QA+Ggzrw+47fVM7uMqPxY9P4UIA="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.10.1_1689061287670_0.5727559784200498"},"_hasShrinkwrap":false},"0.10.2-unstable.1":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.10.2-unstable.1","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"0.10.2-unstable.1+d72fd3f","@sphereon/ssi-sdk-ext.did-utils":"0.14.0","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk.core":"0.15.1","@sphereon/ssi-types":"0.15.1","@sphereon/ssi-sdk-ext.key-manager":"0.14.0","@sphereon/ssi-sdk-ext.kms-local":"0.14.0","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-ext.did-utils":"0.14.0","@sphereon/ssi-sdk.vc-handler-ld-local":"0.15.1","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"d72fd3fd6585c8ad47622b9f5987d733a76ff536","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Overview\n\nAfter Prerequisites and installation part, we will discuss how to setup your own X.509 keys and SSL certificate. What follows is a guide for using this cli agent to connect to a gaia-x compatible Compliance Service (gx-compliance for short).\nBelow you can see a simple workflow scenario of this CLI tool:\n\n![Flow diagram](https://github.com/Sphereon-Opensource/gx-agent/blob/develop/docs/simple-gx-flow.puml)\n\n# Prerequisites and installation\n\n## NodeJS version 18\n\nPlease download NodeJS version 18. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v18.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config            Agent configuration\n  did               Decentralized Identifiers (DID) commands\n  vc                Generic Verifiable Credential commands\n  vp                Generic Verifiable Presentation commands\n  ecosystem         Ecosystem specific commands\n  participant       Participant commands\n  so|service        Service Offering commands\n  export [options]  Exports all agent data so it can be hosted or backed-up\n  help [command]    display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to set up a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Gaia-X Versions\n\nThere has been a couple of gaia-x versions, since there are major changes between versions, this library intends to only support the latest **v1.2.8**\n_support for versions v2206 and v2210 are removed in this release_\n\n- 1.2.8 (latest)\n  _this version is the first version that supports VerifiablePresentation by design._\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used instead. The `--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v1.2.8\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so-called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for its commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now, you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so-called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by its DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Participant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for some of the keys that are mentioned in the context file:\n\n- gx:legalRegistrationNumber\n- gx:parentOrganization\n- gx:subOrganization\n- gx:headquarterAddress\n- gx:legalAddress\n  For a better guide on how to populate your requested field you can take a look at the main shape file: https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\n\n- Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it will always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -sif ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent participant sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ Compliance            │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T14:21:10.896Z │ 763640a06a6c65f79c79d0ff7e549ba1241e06ff260fb98103e67afbc818fe0b82371c2e63907c63a938b836f7dfe85055e8ece07051226516b2143320e020ce │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io      │ 2023-05-29T18:03:00.887Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"2023-05-29T18:03:00.887Z\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `---show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ verified │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The participant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering self-description. This is a so called \"Credential\". You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\nIn the current version you can create an example with calling agent:\n\n_The ServiceOffering and it's example might change in the near future as GAIA-X team are modifying this part_\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ gx_ServiceOffering             │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\n\ngx-agent so sd example -d did:web:nk-gx-agent.eu.ngrok.io\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬────────────────────────────────────────────────┐\n│             type │                                sd-file │                                            did │\n├──────────────────┼────────────────────────────────────────┼────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io                │\n└──────────────────┴────────────────────────────────────────┴────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"urn:uuid:b0aee1c5-a00f-46b4-8142-dbe60903f8b2\",\n  \"credentialSubject\": {\n    \"id\": \"https://nk-gx-agent.eu.ngrok.io\",\n    \"type\": \"gx:ServiceOffering\",\n    \"gx:providedBy\": {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\"\n    },\n    \"gx:policy\": \"\",\n    \"gx:termsAndConditions\": {\n      \"gx:URL\": \"http://termsandconds.com\",\n      \"gx:hash\": \"d8402a23de560f5ab34b22d1a142feb9e13b3143\"\n    },\n    \"gx:dataAccountExport\": {\n      \"gx:requestType\": \"API\",\n      \"gx:accessType\": \"digital\",\n      \"gx:formatType\": \"application/json\"\n    }\n  },\n  \"type\": \"VerifiableCredential\"\n}\n\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the ServiceOffering self-description input file. \n```shell\ngx-agent so sd submit -sof service-offering-input-credential.json -sid <id>  \n```\nFor the id, see \"gx-agent vc list\"\nIt sends that in\nas a Verifiable Presentation with previously fetched ComplianceCredential and Participant SelfDescription to the Ecosystem Compliance service as configured in your agent.yml file.\n```json\n{\n  \"type\": [\"VerifiablePresentation\"],\n  \"@context\": [\"https://www.w3.org/2018/credentials/v1\"],\n  \"verifiableCredential\": [\n    { // Your LegalParticipant self-description VerifiableCredential },\n    { // Your ServiceOffering self-description  VerifiableCredential },\n    { // Your LegalParticipant Compliance Credential Signed by Gaia-X Compliance service },\n  ],\n  \"holder\": \"did:web:4c30-2001-1c04-2b10-ee00-e7d5-abed-7e72-9d92.ngrok-free.app\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-06-01T08:47:10Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..h-rEB7ZPqRCh4Pb9eXK7iX4PEtwF9GdHlrrMR6JSnybVMsxnKcN5tBgqJx33dSIXyPtPSciA2rcp2d7qyQ_tr60oD2dMwu2xnYqgRL67iIkGfg8jIRpunjrZG2PQXPK61ziZvGo4HwuVztY5bwZAqtGTKRs7dWona3U7q2uGsELHojFoHIHfR_j0RPSxLWh8ek_8ZNE13aNVR9QvPwUcxEJ9OGhifhO6XVwwFUDtNtgbGqIU4mwdSC6DU2h6yUsYSK2pu7SRj7qrq4cDbp70OAuLwV8Sywg5IqxuJKKlJZq5YJy_7hgBSvr3RcqeY8BSFr7-H2QGg2n9HuWRIKuwNg\"\n  }\n}\n```\n\nAnd you Ecosystem Compliance Service will send you another ComplianceCredential in response:\n\n```json\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu//development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\"VerifiableCredential\"],\n  \"id\": \"https://nk-eco-compliance.eu.ngrok.io/credential-offers/67645d91-6bb5-4661-a6d1-2d36dce30172\",\n  \"issuer\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n  \"issuanceDate\": \"2023-05-31T14:10:01.794Z\",\n  \"expirationDate\": \"2023-08-29T14:10:01.794Z\",\n  \"credentialSubject\": [\n    {\n      \"type\": \"gx:compliance\",\n      \"id\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n      \"integrity\": \"sha256-d03feb54fedcb3ed0411f723bdd8b19e928d742a49f4c7ca109979e08ac83974\"\n    },\n    {\n      \"type\": \"gx:compliance\",\n      \"id\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n      \"integrity\": \"sha256-198332fad39100e726dcc94bd1c68dfbee2db02befc12c92e35e7648b4399336\"\n    },\n    {\n      \"type\": \"gx:compliance\",\n      \"id\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n      \"integrity\": \"sha256-11fb3ded1ce29b06c5ad15f2bcc8bf1eac41973e70289bf41600aeb1dffe5356\"\n    }\n  ],\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-31T14:10:02.314Z\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..AbRrpo2qbgaCS6HAykU6PACi37iFxlviyu2hxrfhhjhvmz7sItIPFMQc_fj-qGyXD6Zr_LoA2aR5kFE2w4zgu0oEP8Mmudf4fTKzl-3vPNY9lfEUf9tLg_LxLzivs24C2Vz4y2--r2BkNeeXTJ7_pnlBWuDoVPNm3gcrfcT69VcLWmZpErOqhbHTmqafoklr4iGOs7ehU9TGxXS7JptGglAZ_caBVfHvIQQi1MP31mQeIJk7U_t7KohW4Y5ZQKjBL36OL2OqPprZhBEcouOGqI82fRKxAdq22AIjFkgarg9QavwLlq1F_F0qxshpR_QGBE55LV9uU6NJ877Is2sa_w\",\n    \"verificationMethod\": \"did:web:nk-eco-compliance.eu.ngrok.io#JWK2020-RSA\"\n  }\n}\n```\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌─────────────────────┬───────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│               types │                                issuer │                         subject │            issuance-date │                                                               id │\n├─────────────────────┼───────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ gx:LegalParticipant │ did:web:nk-gx-agent.eu.ngrok.io       │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T13:08:29.888Z │ <participant sd id>                                              │\n│ ServiceOffering     │ did:web:nk-gx-agent.eu.ngrok.io       │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T13:08:29.888Z │ <service offering sd id>                                         │\n│          Compliance │ did:web:nk-gx-compliance.eu.ngrok.io  │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T14:10:52.037Z │ <participant compliance id from gx-compliance>                   │\n│          Compliance │ did:web:nk-eco-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T14:26:49.870Z │ <participant and service offering compliance from eco-compliance>│\n└─────────────────────┴───────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────┘\n\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.10.2-unstable.1","_nodeVersion":"16.20.2","_npmVersion":"lerna/6.5.0/node@v16.20.2+x64 (linux)","dist":{"integrity":"sha512-xkZPL9sN+Wn787rpuLM84Wk4I3d6A9WdrdoRLc+NCAxIiJQloRtbf3Kdh66VAkIb5TY95F5He+yzb1Ce/WjkyA==","shasum":"c9f66d7485fabd1667577095127affc612b2c3fb","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.10.2-unstable.1.tgz","fileCount":47,"unpackedSize":381460,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQC3IbckpyhH/TBimQ/cA99oSEwCu9QDizt9yIzr/kmNdgIgXMv71YCvGO5bn4B20pyPBagZX3zW7DxVKEsgX3JbUPY="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.10.2-unstable.1_1694643316558_0.7814164476585834"},"_hasShrinkwrap":false},"0.10.2-unstable.2":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.10.2-unstable.2","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"0.10.2-unstable.2+fdede5d","@sphereon/ssi-sdk-ext.did-utils":"0.14.0","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk.core":"0.15.1","@sphereon/ssi-types":"0.15.1","@sphereon/ssi-sdk-ext.key-manager":"0.14.0","@sphereon/ssi-sdk-ext.kms-local":"0.14.0","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-ext.did-utils":"0.14.0","@sphereon/ssi-sdk.vc-handler-ld-local":"0.15.1","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"fdede5dadf19a4f01ed3563a37288a779a250997","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Overview\n\nAfter Prerequisites and installation part, we will discuss how to setup your own X.509 keys and SSL certificate. What follows is a guide for using this cli agent to connect to a gaia-x compatible Compliance Service (gx-compliance for short).\nBelow you can see a simple workflow scenario of this CLI tool:\n\n![Flow diagram](https://github.com/Sphereon-Opensource/gx-agent/blob/develop/docs/simple-gx-flow.puml)\n\n# Prerequisites and installation\n\n## NodeJS version 18\n\nPlease download NodeJS version 18. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v18.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config            Agent configuration\n  did               Decentralized Identifiers (DID) commands\n  vc                Generic Verifiable Credential commands\n  vp                Generic Verifiable Presentation commands\n  ecosystem         Ecosystem specific commands\n  participant       Participant commands\n  so|service        Service Offering commands\n  export [options]  Exports all agent data so it can be hosted or backed-up\n  help [command]    display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to set up a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Gaia-X Versions\n\nThere has been a couple of gaia-x versions, since there are major changes between versions, this library intends to only support the latest **v1.2.8**\n_support for versions v2206 and v2210 are removed in this release_\n\n- 1.2.8 (latest)\n  _this version is the first version that supports VerifiablePresentation by design._\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used instead. The `--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v1.2.8\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so-called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for its commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now, you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so-called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by its DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Participant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for some of the keys that are mentioned in the context file:\n\n- gx:legalRegistrationNumber\n- gx:parentOrganization\n- gx:subOrganization\n- gx:headquarterAddress\n- gx:legalAddress\n  For a better guide on how to populate your requested field you can take a look at the main shape file: https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\n\n- Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it will always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -sif ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent participant sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ Compliance            │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T14:21:10.896Z │ 763640a06a6c65f79c79d0ff7e549ba1241e06ff260fb98103e67afbc818fe0b82371c2e63907c63a938b836f7dfe85055e8ece07051226516b2143320e020ce │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io      │ 2023-05-29T18:03:00.887Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"2023-05-29T18:03:00.887Z\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `---show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ verified │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The participant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering self-description. This is a so called \"Credential\". You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\nIn the current version you can create an example with calling agent:\n\n_The ServiceOffering and it's example might change in the near future as GAIA-X team are modifying this part_\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ gx_ServiceOffering             │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\n\ngx-agent so sd example -d did:web:nk-gx-agent.eu.ngrok.io\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬────────────────────────────────────────────────┐\n│             type │                                sd-file │                                            did │\n├──────────────────┼────────────────────────────────────────┼────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io                │\n└──────────────────┴────────────────────────────────────────┴────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"urn:uuid:b0aee1c5-a00f-46b4-8142-dbe60903f8b2\",\n  \"credentialSubject\": {\n    \"id\": \"https://nk-gx-agent.eu.ngrok.io\",\n    \"type\": \"gx:ServiceOffering\",\n    \"gx:providedBy\": {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\"\n    },\n    \"gx:policy\": \"\",\n    \"gx:termsAndConditions\": {\n      \"gx:URL\": \"http://termsandconds.com\",\n      \"gx:hash\": \"d8402a23de560f5ab34b22d1a142feb9e13b3143\"\n    },\n    \"gx:dataAccountExport\": {\n      \"gx:requestType\": \"API\",\n      \"gx:accessType\": \"digital\",\n      \"gx:formatType\": \"application/json\"\n    }\n  },\n  \"type\": \"VerifiableCredential\"\n}\n\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the ServiceOffering self-description input file. \n```shell\ngx-agent so sd submit -sof service-offering-input-credential.json -sid <id>  \n```\nFor the id, see \"gx-agent vc list\"\nIt sends that in\nas a Verifiable Presentation with previously fetched ComplianceCredential and Participant SelfDescription to the Ecosystem Compliance service as configured in your agent.yml file.\n```json\n{\n  \"type\": [\"VerifiablePresentation\"],\n  \"@context\": [\"https://www.w3.org/2018/credentials/v1\"],\n  \"verifiableCredential\": [\n    { // Your LegalParticipant self-description VerifiableCredential },\n    { // Your ServiceOffering self-description  VerifiableCredential },\n    { // Your LegalParticipant Compliance Credential Signed by Gaia-X Compliance service },\n  ],\n  \"holder\": \"did:web:4c30-2001-1c04-2b10-ee00-e7d5-abed-7e72-9d92.ngrok-free.app\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-06-01T08:47:10Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..h-rEB7ZPqRCh4Pb9eXK7iX4PEtwF9GdHlrrMR6JSnybVMsxnKcN5tBgqJx33dSIXyPtPSciA2rcp2d7qyQ_tr60oD2dMwu2xnYqgRL67iIkGfg8jIRpunjrZG2PQXPK61ziZvGo4HwuVztY5bwZAqtGTKRs7dWona3U7q2uGsELHojFoHIHfR_j0RPSxLWh8ek_8ZNE13aNVR9QvPwUcxEJ9OGhifhO6XVwwFUDtNtgbGqIU4mwdSC6DU2h6yUsYSK2pu7SRj7qrq4cDbp70OAuLwV8Sywg5IqxuJKKlJZq5YJy_7hgBSvr3RcqeY8BSFr7-H2QGg2n9HuWRIKuwNg\"\n  }\n}\n```\n\nAnd you Ecosystem Compliance Service will send you another ComplianceCredential in response:\n\n```json\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu//development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\"VerifiableCredential\"],\n  \"id\": \"https://nk-eco-compliance.eu.ngrok.io/credential-offers/67645d91-6bb5-4661-a6d1-2d36dce30172\",\n  \"issuer\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n  \"issuanceDate\": \"2023-05-31T14:10:01.794Z\",\n  \"expirationDate\": \"2023-08-29T14:10:01.794Z\",\n  \"credentialSubject\": [\n    {\n      \"type\": \"gx:compliance\",\n      \"id\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n      \"integrity\": \"sha256-d03feb54fedcb3ed0411f723bdd8b19e928d742a49f4c7ca109979e08ac83974\"\n    },\n    {\n      \"type\": \"gx:compliance\",\n      \"id\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n      \"integrity\": \"sha256-198332fad39100e726dcc94bd1c68dfbee2db02befc12c92e35e7648b4399336\"\n    },\n    {\n      \"type\": \"gx:compliance\",\n      \"id\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n      \"integrity\": \"sha256-11fb3ded1ce29b06c5ad15f2bcc8bf1eac41973e70289bf41600aeb1dffe5356\"\n    }\n  ],\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-31T14:10:02.314Z\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..AbRrpo2qbgaCS6HAykU6PACi37iFxlviyu2hxrfhhjhvmz7sItIPFMQc_fj-qGyXD6Zr_LoA2aR5kFE2w4zgu0oEP8Mmudf4fTKzl-3vPNY9lfEUf9tLg_LxLzivs24C2Vz4y2--r2BkNeeXTJ7_pnlBWuDoVPNm3gcrfcT69VcLWmZpErOqhbHTmqafoklr4iGOs7ehU9TGxXS7JptGglAZ_caBVfHvIQQi1MP31mQeIJk7U_t7KohW4Y5ZQKjBL36OL2OqPprZhBEcouOGqI82fRKxAdq22AIjFkgarg9QavwLlq1F_F0qxshpR_QGBE55LV9uU6NJ877Is2sa_w\",\n    \"verificationMethod\": \"did:web:nk-eco-compliance.eu.ngrok.io#JWK2020-RSA\"\n  }\n}\n```\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌─────────────────────┬───────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│               types │                                issuer │                         subject │            issuance-date │                                                               id │\n├─────────────────────┼───────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ gx:LegalParticipant │ did:web:nk-gx-agent.eu.ngrok.io       │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T13:08:29.888Z │ <participant sd id>                                              │\n│ ServiceOffering     │ did:web:nk-gx-agent.eu.ngrok.io       │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T13:08:29.888Z │ <service offering sd id>                                         │\n│          Compliance │ did:web:nk-gx-compliance.eu.ngrok.io  │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T14:10:52.037Z │ <participant compliance id from gx-compliance>                   │\n│          Compliance │ did:web:nk-eco-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T14:26:49.870Z │ <participant and service offering compliance from eco-compliance>│\n└─────────────────────┴───────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────┘\n\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.10.2-unstable.2","_nodeVersion":"16.20.2","_npmVersion":"lerna/6.5.0/node@v16.20.2+x64 (linux)","dist":{"integrity":"sha512-iz8UqMAK4T9ZiiVCaQ1sj/B7hA0B2sSi0gbyjJ5O/Mui2PIFfTftGUFxFFeKfTHkBBkDnrL/UIHQp9WOzR+FUA==","shasum":"4ab90725cff5d0091c3ae96bc65463b2f2596dbd","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.10.2-unstable.2.tgz","fileCount":47,"unpackedSize":381460,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCgdLea4Q7TktZ4a3Hxcpj/plS5UvRq1vIWMLNR90FJIgIhANmxgIcgVhWlIssxZGtpeV89NKjoQYqe45xy4UKgNgnF"}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.10.2-unstable.2_1694706105524_0.8657529828500585"},"_hasShrinkwrap":false},"0.10.2-next.3":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.10.2-next.3","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"0.10.2-next.3+3de0b10","@sphereon/ssi-sdk-ext.did-utils":"0.14.0","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk.core":"0.15.1","@sphereon/ssi-types":"0.15.1","@sphereon/ssi-sdk-ext.key-manager":"0.14.0","@sphereon/ssi-sdk-ext.kms-local":"0.14.0","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-ext.did-utils":"0.14.0","@sphereon/ssi-sdk.vc-handler-ld-local":"0.15.1","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"3de0b1037b8fe436a237e41f5b86d49cbe21e861","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Overview\n\nAfter Prerequisites and installation part, we will discuss how to setup your own X.509 keys and SSL certificate. What follows is a guide for using this cli agent to connect to a gaia-x compatible Compliance Service (gx-compliance for short).\nBelow you can see a simple workflow scenario of this CLI tool:\n\n![Flow diagram](https://github.com/Sphereon-Opensource/gx-agent/blob/develop/docs/simple-gx-flow.puml)\n\n# Prerequisites and installation\n\n## NodeJS version 18\n\nPlease download NodeJS version 18. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v18.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config            Agent configuration\n  did               Decentralized Identifiers (DID) commands\n  vc                Generic Verifiable Credential commands\n  vp                Generic Verifiable Presentation commands\n  ecosystem         Ecosystem specific commands\n  participant       Participant commands\n  so|service        Service Offering commands\n  export [options]  Exports all agent data so it can be hosted or backed-up\n  help [command]    display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to set up a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Gaia-X Versions\n\nThere has been a couple of gaia-x versions, since there are major changes between versions, this library intends to only support the latest **v1.2.8**\n_support for versions v2206 and v2210 are removed in this release_\n\n- 1.2.8 (latest)\n  _this version is the first version that supports VerifiablePresentation by design._\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used instead. The `--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v1.2.8\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so-called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for its commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now, you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so-called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by its DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Participant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for some of the keys that are mentioned in the context file:\n\n- gx:legalRegistrationNumber\n- gx:parentOrganization\n- gx:subOrganization\n- gx:headquarterAddress\n- gx:legalAddress\n  For a better guide on how to populate your requested field you can take a look at the main shape file: https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\n\n- Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it will always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -sif ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent participant sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ Compliance            │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T14:21:10.896Z │ 763640a06a6c65f79c79d0ff7e549ba1241e06ff260fb98103e67afbc818fe0b82371c2e63907c63a938b836f7dfe85055e8ece07051226516b2143320e020ce │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io      │ 2023-05-29T18:03:00.887Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"2023-05-29T18:03:00.887Z\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `---show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ verified │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The participant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering self-description. This is a so called \"Credential\". You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\nIn the current version you can create an example with calling agent:\n\n_The ServiceOffering and it's example might change in the near future as GAIA-X team are modifying this part_\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ gx_ServiceOffering             │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\n\ngx-agent so sd example -d did:web:nk-gx-agent.eu.ngrok.io\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬────────────────────────────────────────────────┐\n│             type │                                sd-file │                                            did │\n├──────────────────┼────────────────────────────────────────┼────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io                │\n└──────────────────┴────────────────────────────────────────┴────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"urn:uuid:b0aee1c5-a00f-46b4-8142-dbe60903f8b2\",\n  \"credentialSubject\": {\n    \"id\": \"https://nk-gx-agent.eu.ngrok.io\",\n    \"type\": \"gx:ServiceOffering\",\n    \"gx:providedBy\": {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\"\n    },\n    \"gx:policy\": \"\",\n    \"gx:termsAndConditions\": {\n      \"gx:URL\": \"http://termsandconds.com\",\n      \"gx:hash\": \"d8402a23de560f5ab34b22d1a142feb9e13b3143\"\n    },\n    \"gx:dataAccountExport\": {\n      \"gx:requestType\": \"API\",\n      \"gx:accessType\": \"digital\",\n      \"gx:formatType\": \"application/json\"\n    }\n  },\n  \"type\": \"VerifiableCredential\"\n}\n\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the ServiceOffering self-description input file. \n```shell\ngx-agent so sd submit -sof service-offering-input-credential.json -sid <id>  \n```\nFor the id, see \"gx-agent vc list\"\nIt sends that in\nas a Verifiable Presentation with previously fetched ComplianceCredential and Participant SelfDescription to the Ecosystem Compliance service as configured in your agent.yml file.\n```json\n{\n  \"type\": [\"VerifiablePresentation\"],\n  \"@context\": [\"https://www.w3.org/2018/credentials/v1\"],\n  \"verifiableCredential\": [\n    { // Your LegalParticipant self-description VerifiableCredential },\n    { // Your ServiceOffering self-description  VerifiableCredential },\n    { // Your LegalParticipant Compliance Credential Signed by Gaia-X Compliance service },\n  ],\n  \"holder\": \"did:web:4c30-2001-1c04-2b10-ee00-e7d5-abed-7e72-9d92.ngrok-free.app\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-06-01T08:47:10Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..h-rEB7ZPqRCh4Pb9eXK7iX4PEtwF9GdHlrrMR6JSnybVMsxnKcN5tBgqJx33dSIXyPtPSciA2rcp2d7qyQ_tr60oD2dMwu2xnYqgRL67iIkGfg8jIRpunjrZG2PQXPK61ziZvGo4HwuVztY5bwZAqtGTKRs7dWona3U7q2uGsELHojFoHIHfR_j0RPSxLWh8ek_8ZNE13aNVR9QvPwUcxEJ9OGhifhO6XVwwFUDtNtgbGqIU4mwdSC6DU2h6yUsYSK2pu7SRj7qrq4cDbp70OAuLwV8Sywg5IqxuJKKlJZq5YJy_7hgBSvr3RcqeY8BSFr7-H2QGg2n9HuWRIKuwNg\"\n  }\n}\n```\n\nAnd you Ecosystem Compliance Service will send you another ComplianceCredential in response:\n\n```json\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu//development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\"VerifiableCredential\"],\n  \"id\": \"https://nk-eco-compliance.eu.ngrok.io/credential-offers/67645d91-6bb5-4661-a6d1-2d36dce30172\",\n  \"issuer\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n  \"issuanceDate\": \"2023-05-31T14:10:01.794Z\",\n  \"expirationDate\": \"2023-08-29T14:10:01.794Z\",\n  \"credentialSubject\": [\n    {\n      \"type\": \"gx:compliance\",\n      \"id\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n      \"integrity\": \"sha256-d03feb54fedcb3ed0411f723bdd8b19e928d742a49f4c7ca109979e08ac83974\"\n    },\n    {\n      \"type\": \"gx:compliance\",\n      \"id\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n      \"integrity\": \"sha256-198332fad39100e726dcc94bd1c68dfbee2db02befc12c92e35e7648b4399336\"\n    },\n    {\n      \"type\": \"gx:compliance\",\n      \"id\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n      \"integrity\": \"sha256-11fb3ded1ce29b06c5ad15f2bcc8bf1eac41973e70289bf41600aeb1dffe5356\"\n    }\n  ],\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-31T14:10:02.314Z\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..AbRrpo2qbgaCS6HAykU6PACi37iFxlviyu2hxrfhhjhvmz7sItIPFMQc_fj-qGyXD6Zr_LoA2aR5kFE2w4zgu0oEP8Mmudf4fTKzl-3vPNY9lfEUf9tLg_LxLzivs24C2Vz4y2--r2BkNeeXTJ7_pnlBWuDoVPNm3gcrfcT69VcLWmZpErOqhbHTmqafoklr4iGOs7ehU9TGxXS7JptGglAZ_caBVfHvIQQi1MP31mQeIJk7U_t7KohW4Y5ZQKjBL36OL2OqPprZhBEcouOGqI82fRKxAdq22AIjFkgarg9QavwLlq1F_F0qxshpR_QGBE55LV9uU6NJ877Is2sa_w\",\n    \"verificationMethod\": \"did:web:nk-eco-compliance.eu.ngrok.io#JWK2020-RSA\"\n  }\n}\n```\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌─────────────────────┬───────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│               types │                                issuer │                         subject │            issuance-date │                                                               id │\n├─────────────────────┼───────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ gx:LegalParticipant │ did:web:nk-gx-agent.eu.ngrok.io       │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T13:08:29.888Z │ <participant sd id>                                              │\n│ ServiceOffering     │ did:web:nk-gx-agent.eu.ngrok.io       │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T13:08:29.888Z │ <service offering sd id>                                         │\n│          Compliance │ did:web:nk-gx-compliance.eu.ngrok.io  │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T14:10:52.037Z │ <participant compliance id from gx-compliance>                   │\n│          Compliance │ did:web:nk-eco-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T14:26:49.870Z │ <participant and service offering compliance from eco-compliance>│\n└─────────────────────┴───────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────┘\n\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.10.2-next.3","_nodeVersion":"16.20.2","_npmVersion":"lerna/6.5.0/node@v16.20.2+x64 (linux)","dist":{"integrity":"sha512-AjzZnk71Cudnuy+fnRCAn0xEtnxhDbP47HM+s1LLMkfRmri5nyH7zntyPUbaw3JTGhMyQLPR0rcqj9RyzJAa4w==","shasum":"ae38f883e94854628135f9e1b0cc0027eff1b41b","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.10.2-next.3.tgz","fileCount":47,"unpackedSize":381452,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQDKKVmTnynj1p+G2oL/USZXtQPyY9YqRYgp2hSbGr+ljwIhAJ4nA/3JwjYuYOu+p37aQetkVOGsTTzR43W/uyEXPwqO"}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.10.2-next.3_1695019577479_0.15205801512700368"},"_hasShrinkwrap":false},"0.10.2-next.4":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.10.2-next.4","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"0.10.2-next.4+b5dfcbb","@sphereon/ssi-sdk-ext.did-utils":"0.14.0","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk.core":"0.15.1","@sphereon/ssi-types":"0.15.1","@sphereon/ssi-sdk-ext.key-manager":"0.14.0","@sphereon/ssi-sdk-ext.kms-local":"0.14.0","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-ext.did-utils":"0.14.0","@sphereon/ssi-sdk.vc-handler-ld-local":"0.15.1","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"b5dfcbbfc3d8888bab36d885a6b8f443548ad862","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Overview\n\nAfter Prerequisites and installation part, we will discuss how to setup your own X.509 keys and SSL certificate. What follows is a guide for using this cli agent to connect to a gaia-x compatible Compliance Service (gx-compliance for short).\nBelow you can see a simple workflow scenario of this CLI tool:\n\n![Flow diagram](https://github.com/Sphereon-Opensource/gx-agent/blob/develop/docs/simple-gx-flow.puml)\n\n# Prerequisites and installation\n\n## NodeJS version 18\n\nPlease download NodeJS version 18. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v18.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config            Agent configuration\n  did               Decentralized Identifiers (DID) commands\n  vc                Generic Verifiable Credential commands\n  vp                Generic Verifiable Presentation commands\n  ecosystem         Ecosystem specific commands\n  participant       Participant commands\n  so|service        Service Offering commands\n  export [options]  Exports all agent data so it can be hosted or backed-up\n  help [command]    display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to set up a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Gaia-X Versions\n\nThere has been a couple of gaia-x versions, since there are major changes between versions, this library intends to only support the latest **v1.2.8**\n_support for versions v2206 and v2210 are removed in this release_\n\n- 1.2.8 (latest)\n  _this version is the first version that supports VerifiablePresentation by design._\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used instead. The `--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v1.2.8\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so-called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for its commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now, you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so-called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by its DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Participant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for some of the keys that are mentioned in the context file:\n\n- gx:legalRegistrationNumber\n- gx:parentOrganization\n- gx:subOrganization\n- gx:headquarterAddress\n- gx:legalAddress\n  For a better guide on how to populate your requested field you can take a look at the main shape file: https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\n\n- Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it will always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -sif ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent participant sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ Compliance            │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T14:21:10.896Z │ 763640a06a6c65f79c79d0ff7e549ba1241e06ff260fb98103e67afbc818fe0b82371c2e63907c63a938b836f7dfe85055e8ece07051226516b2143320e020ce │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io      │ 2023-05-29T18:03:00.887Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"2023-05-29T18:03:00.887Z\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `---show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ verified │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The participant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering self-description. This is a so called \"Credential\". You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\nIn the current version you can create an example with calling agent:\n\n_The ServiceOffering and it's example might change in the near future as GAIA-X team are modifying this part_\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ gx_ServiceOffering             │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\n\ngx-agent so sd example -d did:web:nk-gx-agent.eu.ngrok.io\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬────────────────────────────────────────────────┐\n│             type │                                sd-file │                                            did │\n├──────────────────┼────────────────────────────────────────┼────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io                │\n└──────────────────┴────────────────────────────────────────┴────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"urn:uuid:b0aee1c5-a00f-46b4-8142-dbe60903f8b2\",\n  \"credentialSubject\": {\n    \"id\": \"https://nk-gx-agent.eu.ngrok.io\",\n    \"type\": \"gx:ServiceOffering\",\n    \"gx:providedBy\": {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\"\n    },\n    \"gx:policy\": \"\",\n    \"gx:termsAndConditions\": {\n      \"gx:URL\": \"http://termsandconds.com\",\n      \"gx:hash\": \"d8402a23de560f5ab34b22d1a142feb9e13b3143\"\n    },\n    \"gx:dataAccountExport\": {\n      \"gx:requestType\": \"API\",\n      \"gx:accessType\": \"digital\",\n      \"gx:formatType\": \"application/json\"\n    }\n  },\n  \"type\": \"VerifiableCredential\"\n}\n\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the ServiceOffering self-description input file.\n\n```shell\ngx-agent so sd submit -sof service-offering-input-credential.json -sid <id>\n```\n\nFor the id, see \"gx-agent vc list\"\nIt sends that in\nas a Verifiable Presentation with previously fetched ComplianceCredential and Participant SelfDescription to the Ecosystem Compliance service as configured in your agent.yml file.\n\n```json\n{\n  \"type\": [\"VerifiablePresentation\"],\n  \"@context\": [\"https://www.w3.org/2018/credentials/v1\"],\n  \"verifiableCredential\": [\n    { // Your LegalParticipant self-description VerifiableCredential },\n    { // Your ServiceOffering self-description  VerifiableCredential },\n    { // Your LegalParticipant Compliance Credential Signed by Gaia-X Compliance service },\n  ],\n  \"holder\": \"did:web:4c30-2001-1c04-2b10-ee00-e7d5-abed-7e72-9d92.ngrok-free.app\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-06-01T08:47:10Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..h-rEB7ZPqRCh4Pb9eXK7iX4PEtwF9GdHlrrMR6JSnybVMsxnKcN5tBgqJx33dSIXyPtPSciA2rcp2d7qyQ_tr60oD2dMwu2xnYqgRL67iIkGfg8jIRpunjrZG2PQXPK61ziZvGo4HwuVztY5bwZAqtGTKRs7dWona3U7q2uGsELHojFoHIHfR_j0RPSxLWh8ek_8ZNE13aNVR9QvPwUcxEJ9OGhifhO6XVwwFUDtNtgbGqIU4mwdSC6DU2h6yUsYSK2pu7SRj7qrq4cDbp70OAuLwV8Sywg5IqxuJKKlJZq5YJy_7hgBSvr3RcqeY8BSFr7-H2QGg2n9HuWRIKuwNg\"\n  }\n}\n```\n\nAnd you Ecosystem Compliance Service will send you another ComplianceCredential in response:\n\n```json\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu//development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\"VerifiableCredential\"],\n  \"id\": \"https://nk-eco-compliance.eu.ngrok.io/credential-offers/67645d91-6bb5-4661-a6d1-2d36dce30172\",\n  \"issuer\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n  \"issuanceDate\": \"2023-05-31T14:10:01.794Z\",\n  \"expirationDate\": \"2023-08-29T14:10:01.794Z\",\n  \"credentialSubject\": [\n    {\n      \"type\": \"gx:compliance\",\n      \"id\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n      \"integrity\": \"sha256-d03feb54fedcb3ed0411f723bdd8b19e928d742a49f4c7ca109979e08ac83974\"\n    },\n    {\n      \"type\": \"gx:compliance\",\n      \"id\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n      \"integrity\": \"sha256-198332fad39100e726dcc94bd1c68dfbee2db02befc12c92e35e7648b4399336\"\n    },\n    {\n      \"type\": \"gx:compliance\",\n      \"id\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n      \"integrity\": \"sha256-11fb3ded1ce29b06c5ad15f2bcc8bf1eac41973e70289bf41600aeb1dffe5356\"\n    }\n  ],\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-31T14:10:02.314Z\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..AbRrpo2qbgaCS6HAykU6PACi37iFxlviyu2hxrfhhjhvmz7sItIPFMQc_fj-qGyXD6Zr_LoA2aR5kFE2w4zgu0oEP8Mmudf4fTKzl-3vPNY9lfEUf9tLg_LxLzivs24C2Vz4y2--r2BkNeeXTJ7_pnlBWuDoVPNm3gcrfcT69VcLWmZpErOqhbHTmqafoklr4iGOs7ehU9TGxXS7JptGglAZ_caBVfHvIQQi1MP31mQeIJk7U_t7KohW4Y5ZQKjBL36OL2OqPprZhBEcouOGqI82fRKxAdq22AIjFkgarg9QavwLlq1F_F0qxshpR_QGBE55LV9uU6NJ877Is2sa_w\",\n    \"verificationMethod\": \"did:web:nk-eco-compliance.eu.ngrok.io#JWK2020-RSA\"\n  }\n}\n```\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌─────────────────────┬───────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│               types │                                issuer │                         subject │            issuance-date │                                                               id │\n├─────────────────────┼───────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ gx:LegalParticipant │ did:web:nk-gx-agent.eu.ngrok.io       │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T13:08:29.888Z │ <participant sd id>                                              │\n│ ServiceOffering     │ did:web:nk-gx-agent.eu.ngrok.io       │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T13:08:29.888Z │ <service offering sd id>                                         │\n│          Compliance │ did:web:nk-gx-compliance.eu.ngrok.io  │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T14:10:52.037Z │ <participant compliance id from gx-compliance>                   │\n│          Compliance │ did:web:nk-eco-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T14:26:49.870Z │ <participant and service offering compliance from eco-compliance>│\n└─────────────────────┴───────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────┘\n\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.10.2-next.4","_nodeVersion":"16.20.2","_npmVersion":"lerna/6.5.0/node@v16.20.2+x64 (linux)","dist":{"integrity":"sha512-gBRJR8I5rw0pal/I7TDPonpyPfVBtDL9cavUtm/FTyib0VfZPeYSx5SdRwdrJHb2NDKRSHLKxVyW9hJBxNqK3A==","shasum":"db191bc42f57a67d99973563b6c2db305d7ebe0a","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.10.2-next.4.tgz","fileCount":47,"unpackedSize":381456,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEYCIQCf9aM7PEEzEO1p/K6kxg/9z/Vwzcpahq7a378iV12l+gIhAMPVHxYgCEs519Z6qZhVH0w868lur2QKFMtZQ9Djfrmt"}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.10.2-next.4_1695020074164_0.04857188509004384"},"_hasShrinkwrap":false},"0.10.2":{"name":"@sphereon/gx-agent-cli","description":"Gaia-X Compliance Client CLI","version":"0.10.2","main":"dist/lib/index.js","types":"dist/lib/index.d.ts","exports":"./dist/lib/index.js","bin":{"gx-agent":"dist/cli.js"},"scripts":{"build":"tsc","watch":"tsc -b --watch"},"dependencies":{"@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@microsoft/api-extractor":"^7.33.6","@microsoft/api-extractor-model":"^7.25.2","@sphereon/gx-agent":"0.10.2","@sphereon/ssi-sdk-ext.did-utils":"0.14.0","@types/blessed":"^0.1.19","@types/swagger-ui-express":"^4.1.3","@types/uuid":"^9.0.0","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","commander":"^9.0.0","console-table-printer":"^2.10.0","cors":"^2.8.5","cross-fetch":"^3.1.4","debug":"^4.3.3","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","dotenv":"^16.0.0","express":"^4.18.2","express-handlebars":"^6.0.2","fuzzy":"^0.1.3","global":"^4.4.0","handlebars":"^4.7.6","inquirer":"^9.1.4","inquirer-autocomplete-prompt":"^3.0.0","json-schema":"^0.4.0","json5":"^2.2.0","jsonpointer":"^5.0.0","nock":"^13.3.0","oas-resolver":"^2.5.3","openapi-types":"^12.0.2","url-parse":"^1.5.10","uuid":"^9.0.0","yaml":"^2.1.3"},"devDependencies":{"@types/debug":"4.1.7","@types/inquirer":"^9.0.3","@types/inquirer-autocomplete-prompt":"^3.0.0","@types/node":"16.11.7","@types/node-fetch":"3.0.3","@types/passport-http-bearer":"1.0.37","@types/ws":"8.5.4","typescript":"4.6.4"},"resolutions":{"@sphereon/ssi-sdk.core":"0.15.1","@sphereon/ssi-types":"0.15.1","@sphereon/ssi-sdk-ext.key-manager":"0.14.0","@sphereon/ssi-sdk-ext.kms-local":"0.14.0","@sphereon/did-uni-client":"^0.6.0","@sphereon/ssi-sdk-ext.did-utils":"0.14.0","@sphereon/ssi-sdk.vc-handler-ld-local":"0.15.1","@digitalcredentials/ed25519-verification-key-2020":"3.2.2","@veramo/cli":"4.2.0","@veramo/core":"4.2.0","@veramo/credential-eip712":"4.2.0","@veramo/credential-ld":"4.2.0","@veramo/credential-w3c":"4.2.0","@veramo/data-store":"4.2.0","@veramo/did-comm":"4.2.0","@veramo/did-discovery":"4.2.0","@veramo/did-jwt":"4.2.0","@veramo/did-manager":"4.2.0","@veramo/did-provider-web":"4.2.0","@veramo/did-resolver":"4.2.0","@veramo/key-manager":"4.2.0","@veramo/kms-local":"4.2.0","@veramo/message-handler":"4.2.0","@veramo/utils":"4.2.0","@veramo/did-provider-ethr":"4.2.0","@veramo/did-provider-key":"4.2.0","@veramo/remote-client":"4.2.0","@veramo/remote-server":"4.2.0","@veramo/selective-disclosure":"4.2.0","@veramo/url-handler":"4.2.0","did-jwt":"6.11.6","did-jwt-vc":"3.1.3","ethr-did":"2.3.9"},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"license":"Apache-2.0","keywords":["Gaia-X","Agent","CLI","SSI"],"type":"module","moduleDirectories":["node_modules","lib"],"gitHead":"38b3d93fc1ec7f5fa06e77bf8f89bc16fb6d38b4","bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"homepage":"https://github.com/Sphereon/gx-agent#readme","_id":"@sphereon/gx-agent-cli@0.10.2","_nodeVersion":"16.20.2","_npmVersion":"lerna/6.5.0/node@v16.20.2+x64 (linux)","dist":{"integrity":"sha512-Dj9duN+1bNMOZz7KusncxCAZ47vOzVCa1mbpgMXbVMPOCBIuzp2TPLc3M5ArpiX2Cr/thSK/gAPnk6OYmfoETg==","shasum":"2f1fdc98a7b7e00eab4e0ecf7809aab00aa001d2","tarball":"https://registry.npmjs.org/@sphereon/gx-agent-cli/-/gx-agent-cli-0.10.2.tgz","fileCount":47,"unpackedSize":381426,"signatures":[{"keyid":"SHA256:jl3bwswu80PjjokCgh0o2w5c2U4LhQAE57gj9cz1kzA","sig":"MEUCIQDTt7idvE1Vbrq78wkaN6gq3Kv8xFCHHbwG/4pQtort7wIgWasiBAeDk+YvvgcGsHpy28ZR+KREgjnQPlhyYMrm9FY="}]},"_npmUser":{"name":"nklomp78","email":"dev@sphereon.com"},"directories":{},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages","tmp":"tmp/gx-agent-cli_0.10.2_1695020355463_0.5115071484175959"},"_hasShrinkwrap":false}},"time":{"created":"2023-01-20T12:00:43.954Z","0.1.1-next.6":"2023-01-20T12:00:44.244Z","modified":"2023-09-18T06:59:15.906Z","0.1.1-next.7":"2023-01-20T12:28:45.859Z","0.1.1-next.9":"2023-01-20T23:36:47.235Z","0.1.1-next.10":"2023-01-21T00:01:49.055Z","0.1.1-next.12":"2023-01-21T00:40:05.391Z","0.1.1-next.13":"2023-01-23T05:10:16.445Z","0.1.1-next.14":"2023-01-23T09:45:12.372Z","0.1.1-next.15":"2023-01-23T12:50:52.217Z","0.1.1-next.16":"2023-01-23T13:19:59.730Z","0.1.1-next.17":"2023-01-23T14:04:02.025Z","0.1.1-next.19":"2023-01-23T14:09:27.799Z","0.1.1-next.20":"2023-01-23T14:12:21.460Z","0.1.1-next.22":"2023-01-23T14:47:58.385Z","0.1.1":"2023-01-23T18:23:29.768Z","0.1.2-next.5":"2023-01-26T08:42:05.936Z","0.1.2":"2023-01-26T08:44:34.573Z","0.1.3-next.5":"2023-01-26T13:21:24.195Z","0.1.3-next.8":"2023-01-26T15:20:47.662Z","0.1.3-next.9":"2023-01-26T15:58:51.046Z","0.1.3-next.10":"2023-01-26T16:08:53.555Z","0.1.3-next.11":"2023-01-27T04:22:41.987Z","0.1.3-next.12":"2023-01-27T04:32:27.515Z","0.1.3-next.15":"2023-01-27T10:43:34.751Z","0.1.3-next.16":"2023-01-27T10:55:28.429Z","0.2.0":"2023-01-27T10:57:55.209Z","0.2.1-next.2":"2023-01-27T11:37:07.625Z","0.2.1-next.3":"2023-01-27T11:55:02.178Z","0.2.1-unstable.4":"2023-01-30T14:15:17.484Z","0.2.1-unstable.5":"2023-01-30T15:44:04.020Z","0.2.1-unstable.6":"2023-02-01T15:13:44.787Z","0.2.1-unstable.7":"2023-02-02T09:23:09.274Z","0.2.1-next.12":"2023-02-04T08:04:40.937Z","0.2.1-unstable.21":"2023-02-06T13:51:35.375Z","0.2.1-unstable.22":"2023-02-08T08:10:42.784Z","0.2.1-next.23":"2023-02-08T09:53:49.793Z","0.2.1-next.24":"2023-02-08T14:02:06.661Z","0.2.1-unstable.32":"2023-02-10T13:13:28.739Z","0.2.1-next.32":"2023-02-13T15:13:25.622Z","0.2.1-unstable.55":"2023-02-14T21:46:10.970Z","0.2.1-next.56":"2023-02-14T21:53:30.000Z","0.2.1-next.58":"2023-02-15T00:00:07.733Z","0.2.1":"2023-02-15T07:44:32.111Z","0.2.1-next.61":"2023-02-16T00:07:47.370Z","0.2.2-next.63":"2023-02-16T00:24:51.451Z","0.2.2-next.64":"2023-02-16T00:34:53.000Z","0.3.0":"2023-02-16T00:39:51.784Z","0.3.1-next.1":"2023-02-17T12:35:58.814Z","0.3.1-unstable.2":"2023-03-02T00:58:51.361Z","0.3.1-next.3":"2023-03-02T01:02:29.727Z","0.4.0":"2023-03-02T01:13:25.160Z","0.4.1-next.1":"2023-03-02T01:45:02.762Z","0.4.1":"2023-03-02T01:51:17.498Z","0.4.2-next.2":"2023-03-02T01:59:14.187Z","0.4.2-next.3":"2023-03-02T02:08:21.193Z","0.4.2":"2023-03-02T02:15:34.563Z","0.4.2-next.4":"2023-03-02T02:30:06.875Z","0.4.2-next.6":"2023-03-02T02:37:02.641Z","0.4.2-next.7":"2023-03-02T02:47:25.042Z","0.4.3-next.4":"2023-03-02T02:59:17.742Z","0.4.3":"2023-03-02T03:02:33.192Z","0.4.3-next.6":"2023-03-05T02:13:48.924Z","0.4.3-next.8":"2023-03-05T02:21:41.836Z","0.4.3-next.10":"2023-03-05T02:23:05.413Z","0.4.4-next.7":"2023-03-05T02:24:30.846Z","0.4.4":"2023-03-05T02:32:00.299Z","0.4.5-next.1":"2023-03-05T23:29:44.534Z","0.5.0":"2023-03-05T23:39:14.445Z","0.5.1-next.2":"2023-03-06T09:49:14.569Z","0.5.1-next.3":"2023-03-06T10:05:05.247Z","0.5.1-next.4":"2023-03-06T10:14:21.629Z","0.5.1-next.5":"2023-03-06T10:21:50.484Z","0.5.1-unstable.1":"2023-03-06T12:21:55.420Z","0.5.1-unstable.2":"2023-03-06T12:40:24.554Z","0.5.1-unstable.3":"2023-03-06T14:07:53.944Z","0.5.1-unstable.4":"2023-03-06T14:41:38.146Z","0.5.1-unstable.6":"2023-03-07T10:46:05.294Z","0.5.1-next.12":"2023-03-07T12:48:38.189Z","0.6.0":"2023-03-07T12:59:23.867Z","0.6.1-unstable.1":"2023-03-09T12:01:56.052Z","0.6.1-unstable.3":"2023-03-09T14:25:53.502Z","0.6.1-unstable.4":"2023-03-09T14:35:17.391Z","0.6.1-unstable.5":"2023-03-09T15:22:28.226Z","0.6.1-unstable.6":"2023-03-10T08:34:47.772Z","0.6.1-unstable.8":"2023-03-10T09:52:55.223Z","0.6.1-next.9":"2023-03-10T10:37:25.453Z","0.7.0":"2023-03-10T10:43:32.832Z","0.6.1-next.11":"2023-03-13T13:19:15.990Z","0.6.1-unstable.12":"2023-03-17T14:46:41.646Z","0.6.1-unstable.13":"2023-03-17T14:47:21.576Z","0.6.1-unstable.14":"2023-03-17T15:16:06.888Z","0.6.1-next.16":"2023-03-17T17:24:08.198Z","0.6.1-next.17":"2023-05-23T23:41:18.059Z","0.7.1-next.9":"2023-05-23T23:47:31.995Z","0.8.0":"2023-05-23T23:51:59.295Z","0.8.1-next.1":"2023-05-24T00:35:16.947Z","0.8.1-next.4":"2023-05-24T01:09:23.339Z","0.9.1":"2023-05-24T01:13:20.394Z","0.9.2-next.1":"2023-05-24T01:55:11.427Z","0.9.3":"2023-05-24T01:59:12.760Z","0.9.4-next.0":"2023-05-24T22:44:35.517Z","0.9.4":"2023-05-24T23:31:54.161Z","0.9.4-unstable.1":"2023-05-26T17:07:38.469Z","0.9.4-unstable.2":"2023-05-26T23:04:02.259Z","0.9.4-unstable.5":"2023-06-05T05:21:29.446Z","0.9.4-unstable.6":"2023-06-05T05:44:16.623Z","0.9.4-unstable.8":"2023-06-07T10:10:59.366Z","0.9.4-unstable.9":"2023-06-08T07:30:03.043Z","0.9.4-unstable.10":"2023-06-08T10:36:41.877Z","0.9.4-unstable.11":"2023-06-08T10:38:43.403Z","0.9.4-unstable.12":"2023-06-08T11:27:52.391Z","0.9.4-unstable.13":"2023-06-08T12:08:08.534Z","0.9.5-next.16":"2023-07-10T21:48:46.093Z","0.10.0":"2023-07-10T21:57:49.128Z","0.10.1-next.1":"2023-07-11T07:25:18.168Z","0.10.1":"2023-07-11T07:41:27.781Z","0.10.2-unstable.1":"2023-09-13T22:15:16.795Z","0.10.2-unstable.2":"2023-09-14T15:41:45.686Z","0.10.2-next.3":"2023-09-18T06:46:17.765Z","0.10.2-next.4":"2023-09-18T06:54:34.430Z","0.10.2":"2023-09-18T06:59:15.685Z"},"maintainers":[{"name":"nklomp78","email":"dev@sphereon.com"},{"name":"nklomp","email":"nklomp@sphereon.com"},{"name":"spostma","email":"spostma@sphereon.com"},{"name":"bramtencate","email":"btencate@sphereon.com"}],"description":"Gaia-X Compliance Client CLI","homepage":"https://github.com/Sphereon/gx-agent#readme","keywords":["Gaia-X","Agent","CLI","SSI"],"repository":{"type":"git","url":"git+ssh://git@github.com/Sphereon/gx-agent.git"},"bugs":{"url":"https://github.com/Sphereon/gx-agent/issues"},"license":"Apache-2.0","readme":"<!--suppress HtmlDeprecatedAttribute -->\n<h1 align=\"center\">\n  <br>\n  <a href=\"https://www.sphereon.com\"><img src=\"https://sphereon.com/content/themes/sphereon/assets/img/logo.svg\" alt=\"Sphereon\" width=\"400\"></a>\n  <br>Gaia-X Agent Command Line Interface (CLI) \n  <br>\n</h1>\n\n---\n\n**Warning: This package is in very early development. Breaking changes without notice will happen at this point!**\n\n---\n\n# GX Compliance Agent CLI\n\nThe Gaia-X Compliance Agent Command Line interface, allows you to manage the agent from the command line. Common\nmethods, like creating a DID, generating self-descriptions, acquiring Compliance Credentials from the Compliance Service\nare supported.\n\n# Overview\n\nAfter Prerequisites and installation part, we will discuss how to setup your own X.509 keys and SSL certificate. What follows is a guide for using this cli agent to connect to a gaia-x compatible Compliance Service (gx-compliance for short).\nBelow you can see a simple workflow scenario of this CLI tool:\n\n![Flow diagram](https://github.com/Sphereon-Opensource/gx-agent/blob/develop/docs/simple-gx-flow.puml)\n\n# Prerequisites and installation\n\n## NodeJS version 18\n\nPlease download NodeJS version 18. You can find NodeJS for your computer on the following\npage: https://nodejs.org/en/blog/release/v18.16.0/\nFollow the installation instructions on the nodejs website\n\n## Install the Gaia-X agent CLI tool\n\nAfter installing nodejs open a terminal window or command prompt on your computer. Ideally with elevated permissions.\nType in the following command:\n\n```shell\nnpm install -g @sphereon/gx-agent-cli --no-audit\n```\n\nIf you are using yarn instead of npm (required you to install yarn first separately from nodejs)\n\n```shell\nyarn global add @sphereon/gx-agent-cli\n```\n\n## Check that the CLI is available to you\n\nOpen a new terminal or command prompt on your computer and type\n\n```shell\ngx-agent --help\n\nUsage: cli [options] [command]\n\nOptions:\n  -h, --help      display help for command\n\nCommands:\n  config            Agent configuration\n  did               Decentralized Identifiers (DID) commands\n  vc                Generic Verifiable Credential commands\n  vp                Generic Verifiable Presentation commands\n  ecosystem         Ecosystem specific commands\n  participant       Participant commands\n  so|service        Service Offering commands\n  export [options]  Exports all agent data so it can be hosted or backed-up\n  help [command]    display help for command\n```\n\nIf you see an output similar like the above, the Gaia-X Agent CLI is properly installed.\n\n## Create X.509 keys and get SSL certificate\n\nYou will first need to have an existing X.509 EV SSL certificate or create a new\none. [This document](../../docs/X509-setup.md)\nexplains how to set up a new X.509 certificate. Without following the steps in the document you cannot be onboarded as\nGaia-X participant.\n\n# Agent configuration Commands\n\nThe agent requires an `agent.yml` file. This is a config file for the agent. It contains parameters and variables,\ndetermining what methods are available for instance. The `agent.yml` file can either be located in the current\ndirectory, or in a `.gx-agent` directory in your home directory. By default, the `.gx-agent` directory in your home\ndirectory is used, unless the current working directory contains an `agent.yml` file.\n\n## Create configuration\n\nCreates the `agent.yml` agent configuration file. It has one option, which is not mandatory. The `-l/--location` option\ncan have a value of `cwd`, meaning the `agent.yml` file will be written to current working directory, or `home`, meaning\nthe `agent.yml` file will be written to the `.gx-agent` directory in your user home-directory. If no option is\nprovided, `home` will be assumed.\n\n```shell\ngx-agent config create\n\noutput:\n\nCreating agent file: C:\\Users\\example\\.gx-agent\\agent.yml\nDone. Agent file available at: C:\\Users\\example\\.gx-agent\\agent.yml\nPlease check the agent configuration file for any configuration options you wish to modify\n```\n\nWe advise you to use the `home` location, as it means the configuration file is always available no matter from which\ndirectory you invoke the command. Using `cwd` or current working directory is handy, when you want to use distinct\nconfiguration files, for instance if you have to manage more than one domain. Although the agent is capable of handling\nmultiple domains from a single agent, you would need to provide the domain or DID value for most commands when the agent\nmanages multiple domains/DIDs. Having separate configuration files in separate directories then means, you do not have\nto provide the DID/domain values, as the agent will notice you are only managing a single domain/DID.\n\n## Gaia-X Versions\n\nThere has been a couple of gaia-x versions, since there are major changes between versions, this library intends to only support the latest **v1.2.8**\n_support for versions v2206 and v2210 are removed in this release_\n\n- 1.2.8 (latest)\n  _this version is the first version that supports VerifiablePresentation by design._\n\n## Verify configuration\n\nVerifies a Gaia-X `agent.yml` file at a specific file location. If the `-f/--filename` option is omitted the default\nhome-dir location will be used instead. The `--show` option, will display the entire configuration file.\n\nFor technical people or developers. You can also test whether low level agent methods are properly configured and\navailable by providing the `-m/--method` option. For example to test the DID resolution method, you could\nsupply `resolveDid` as `-m/--method` option.\n\n```shell\ngx-agent config verify -f ./agent.yml --show\n\noutput:\n\nversion: 3\ngx:\n  complianceServiceUrl: https://nk-gx-compliance.eu.ngrok.io\n  complianceServiceVersion: v1.2.8\n  dbEncryptionKey: 13455271cbd1bd1a0fc4d9b75cd4d2990de535baf5caadfdf8d8f86664aa7201\n  dbFile: ./db/gx.db.sqlite\n  kmsName: local\nconstants:\n  ... truncated for README\n\nYour Gaia-X agent configuration seems fine. An agent can be created and the 'agent.execute()' method can be called on it.\n```\n\n# DID Commands\n\nGaia-X DIDs currently rely on the so called [DID:web](https://w3c-ccg.github.io/did-method-web/) DID documents and\nmethod.\nThe DID document is responsible for listing public keys associated with the DID and your organizational domain. This DID\nis used to sign Gaia-X self-descriptions and so-called Verifiable Credentials. This allows others to determine that data\nis authentic and not manipulated, originating from your organization.\nFor Gaia-X so called did:web DIDs will be used, meaning DIDs associated with your domain name hosted at a well known\nlocation (https://example.com/.well-known/did.json). The DID will list at least the X.509 Certificate public key\ngenerated from the public certificate you received in the previous step.\n\n**NOTE:** You first will\nhave to get a X509 certificate for your domain and DID:WEB, before you can proceed with creating the DID in the agent.\nMore information can be found [here](./todo)\n\n## Create a DID and import the X.509 certificate\n\nAfter having followed the instructions to obtain an X.509 certificate, you should have the private-key PEM file, the\ncertificate PEM file and the Certificate Authority Chain PEM file ready.\n\nThe below command creates a new DID Document, with the privkey.pem file as private Key input, the cert.pem file as\npublic certificate input and cacerts.pem as the Certificate Chain input. Lastly you need to pass in the domain name that\nwill host the DID document. This domain name needs to be exactly the same as the CN input parameter of the X.509\nCertificate and should match the website name/domain you will be hosting the Gaia-X resources on!\n\nOptionally you can provide a --ca-chain-url argument, if you wish to host the Certificate Chain somewhere else than the\ndefault location.\n\n```shell\ngx-agent did create --private-key-file=path/to/privkey.pem --cert-file=path/to/cert.pem --ca-chain-file=path/to/cacerts.pem --domain=nx-gx-agent.eu.ngrok.io\n\noutput:\n┌──────────┬─────────────────────────────────┬─────────────────────────────────┐\n│ provider │                             DID │                           alias │\n├──────────┼─────────────────────────────────┼─────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │\n└──────────┴─────────────────────────────────┴─────────────────────────────────┘\n```\n\nThe DID Document is now created. You will either export it later, or serve it directly from the Gaia-X Participant\nagent (described later in this document). If you do want to have a quick peek, you could use the below command to\nexplore the database of the agent\n\n## List DIDs\n\nLists all DIDs known to the agent. Normally you will only have one DID:web for your organization. When only one DID is\npresent, the agent will automatically select this DID for its commands. If you have more DIDs available, you should use\nthe -d option available on most commands, to select the appropriate DID\n\n```shell\ngx-agent did list\n\nexample output:\n┌──────────┬──────────────────────────────────────┬──────────────────────────────────────┐\n│ provider │                                  DID │                                alias │\n├──────────┼──────────────────────────────────────┼──────────────────────────────────────┤\n│  did:web │ did:web:nk-gx-agent.eu.ngrok.io      │ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────┴──────────────────────────────────────┴──────────────────────────────────────┘\n```\n\n## Resolve a DID\n\nResolving a DID, means retrieving the DID Document associated with that particular DID document. Since Gaia-X uses did:\nweb, it means accessing the domain name with a well-known location for the DID document,\neg: https://identity.foundation/.well-known/did.json\n\nThe below command allows you to resolve DID document. Not that directly after importing the X.509 certificates and\ncreating the DID in the agent, your domain will not yet host the DID document. You will have to export the DID document\nfirst (see next command). The agent allows you to resolve any DID:web DID, but it can also resolve a DID not yet\nexported and only locally known to the agent. This is handy during the onboarding phase. You will have to provide the '\n-l' or '--local-only' options to enable local agent resolution\n\nExample commands:\n\n```shell\ngx-agent did resolve\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n┌──────────┬───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│    error │                                                                                                           message │\n├──────────┼───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ notFound │ resolver_error: DID must resolve to a valid https URL containing a JSON document: Error: Bad response Bad Gateway │\n└──────────┴───────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nThe above error is expected as long as the DID is not yet exported and hosted at the domain. Let's try again, but\ndirectly ask the agent and with a specific DID:\n\n```shell\ngx-agent did resolve did:web:nk-gx-agent.eu.ngrok.io -l\n\noutput:\n┌──────────────────────────────────────┐\n│                                  DID │\n├──────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │\n└──────────────────────────────────────┘\n\nDID Document:\n{\n  \"@context\": \"https://w3id.org/did/v1\",\n  \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"verificationMethod\": [\n    {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n      \"type\": \"JsonWebKey2020\",\n      \"controller\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n      \"publicKeyJwk\": {\n        \"kty\": \"RSA\",\n        \"n\": \"uUGlbA84qYjmawZ1r9j1rUDAhkrsxdvS7rE7AZIIj41-kNpZw3UU9gPgcRwZIA7TdXewDmU5sLbOXwmNu4WuTlaXBkJAFZ390E5S_fvCBxthE8nMjjyFV8Juj_kZ__00WAHSkZxmsGs6en1AUHhRH74nX8b55Eh5UvysYbP8C6KJlyb8TUpJcOlfLT-RE-1byxgDR4Vnz3r-2kPYxdViUButOGWqKSjSIJtYZi5_kYAQC5zweUBlWeyZ3W5Ai3zRX9MC5_Y6B9fGCZu0__5y6ORCoTOU_hG2U3y7zyMCGIObjCsURhmRSwi30vyE3oIMtBV7YVl4KmrSH2jEg4iaeQ\",\n        \"e\": \"AQAB\",\n        \"x5u\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem\"\n      }\n    }\n  ],\n  \"authentication\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"assertionMethod\": [\n    \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\"\n  ],\n  \"service\": []\n}\n```\n\n## Export a DID and the CA chain\n\nYou will need to host the DID on your domain. For now, you will have to copy the files to your webserver (the agent can\nhost them for you, but that option is not yet available). The document will have to be served from your domain in the\n/.well-known location. The easiest way to accommodate that typically is to create a folder called .well-known in your\nWebsite root directory. The export command already creates that folder for you!\n\nThe below command will export the DID Document in the file did.json and the CA chain in the file fullchain.pem to disk\nin the .well-known directory. Copy the .well-known directory to your webserver.\n\nNote: Do not change the path ot the fullchain.pem file on your webserver. Depending on whether you provided the URL for\nthe CA chain during DID creation, it might be different from below. Since the DID Document references that URL, it needs\nto be resolvable at the correct location!\n\n```shell\ngx-agent did export -p my-export\n\noutput:\n┌──────────────────────────────────────┬───────────────┬────────────────────────────────────────────────────────────────────┐\n│                                  DID │          file │                                                               path │\n├──────────────────────────────────────┼───────────────┼────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io      │      did.json │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/did.json           │\n│ did:web:nk-gx-agent.eu.ngrok.io      │ fullchain.pem │ ./my-export/nk-gx-agent.eu.ngrok.io/.well-known/fullchain.pem      │\n└──────────────────────────────────────┴───────────────┴────────────────────────────────────────────────────────────────────┘\nWell-known DID files have been exported.\nPlease copy everything from my-export/nk-gx-agent.eu.ngrok.io, to your webserver. Do not forget to include the hidden .well-known directory!\n```\n\nAfter you copied the file to the webserver, you should be able to resolve the DID, without using the `-l/--local-only`\noption (see above)\n\n## Delete a DID\n\nWarning, normally you shouldn't be deleting DIDs from your agent. Only do so if you are sure what you are doing.\n\n```shell\ngx-agent did delete did:web:nk-gx-agent.eu.ngrok.io\n```\n\n# Participant onboarding\n\nYou first need to become a Gaia-X compliant participant. In order to do so, you first need to create a participant\nself-description. This is a so-called Credential in a specific order. You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nParticipant Credential, signed by its DID. This allows you to prove to others that you are a Gaia-X participant.\n\nYou can either become compliant in 1 step, or by having 2 extra steps. The benefit of using 2 steps is that you can\nverify the self-description, before sending it in to become compliant. The agent internally creates the same objects, no\nmatter what choice you make.\n\n## Export example participant-input-credential.json\n\nThere is a command to export a template/example for two version of participants self-description to disk. If you want to create a Participant according to v2206 api, you can call it with that specific version `-v v2206`, or you can call it with `-v v2210` to get the new version of Participant Self-Description. _Also calling it without a version param will generate v2210 version of a participant self-description._ You can then edit this example\nself-description with your information.\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\ngx-agent participant sd example -d did:web:nk-gx-agent.eu.ngrok.io --show\n\noutput:\n┌─────────────┬───────────────────────────────────┬──────────────────────────────────────┐\n│        type │                           sd-file │                                  did │\n├─────────────┼───────────────────────────────────┼──────────────────────────────────────┤\n│ participant │ participant-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io      │\n└─────────────┴───────────────────────────────────┴──────────────────────────────────────┘\nExample self-description file has been written to participant-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n}\n\n```\n\nYou now should open the file, and adjust the values with your participant information. Update all\nthe values. Do not add new keys or remove any properties/keys, except for some of the keys that are mentioned in the context file:\n\n- gx:legalRegistrationNumber\n- gx:parentOrganization\n- gx:subOrganization\n- gx:headquarterAddress\n- gx:legalAddress\n  For a better guide on how to populate your requested field you can take a look at the main shape file: https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\n\n- Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be aware that it will always overwrite the existing file!\n\n## Submit the participant self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the self-description input file. It sends that in\nas a\nVerifiable Presentation to the Compliance service as configured in your agent.yml file. The compliance service then will\nverify the Verifiable Presentation, containing the self-description Verifiable Credential. It also performs some checks\non the information provided, like for instance the registration numbers. If everything is okay, it will return a\nCompliance Verifiable Credential to you. That credential denotes you are now a valid Gaia-X participant.\n\nNext to using the input file, you could also submit a self-description if it was already stored in the agent. This means\nyou can provide the ID value of the self-description credential in the agent.\n\nYou can use the `--show` option, to show all the credentials used in the exchange.\n\n```shell\ngx-agent participant sd submit -sif ./participant-input-credential.json\n```\n\nor from an existing agent self-description credential:\n\n```shell\ngx-agent participant sd submit -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef51114\n\noutput:\n┌───────────────────────┬──────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                  type │                               issuer │                         subject │            issuance-date │                                                                                                                               id │\n├───────────────────────┼──────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ Compliance            │ did:web:nk-gx-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T14:21:10.896Z │ 763640a06a6c65f79c79d0ff7e549ba1241e06ff260fb98103e67afbc818fe0b82371c2e63907c63a938b836f7dfe85055e8ece07051226516b2143320e020ce │\n└───────────────────────┴──────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\nNotice that you now have a Participant Credential, which is issued by the compliance server\n\n## List participant self-description credentials\n\nYou can list participant self-descriptions known to the agent. Normally this should only be one for a domain, but you\ncan create new ones for the same domain/did, to update values. You can optionally provide a `-d/--did` option, to\nprovide the DID or domain name for which to list the participant self-description credentials.\n\n```shell\ngx-agent  participant sd list\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-01-26T03:04:58.179Z │ dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a participant self-description credential\n\nTo show the content of a participant self-description credential known to the agent, you can first list all the\nparticipant self-descriptions (see command above). From that output you can get the id value and use that to show the\ncredential.\n\n```shell\ngx-agent participant sd show dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io      │ 2023-05-29T18:03:00.887Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\n    \"VerifiableCredential\"\n  ],\n  \"id\": \"urn:uuid:554db947-e001-431c-ae55-22a781e1f928\",\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"issuanceDate\": \"2023-05-29T18:03:00.887Z\",\n  \"credentialSubject\": {\n    \"id\": \"2023-05-29T18:03:00.887Z\",\n    \"type\": \"gx:LegalParticipant\",\n    \"gx:legalName\": \"Gaia-X European Association for Data and Cloud AISBL\",\n    \"gx:legalRegistrationNumber\": {\n      \"gx:vatID\": \"BE0762747721\"\n    },\n    \"gx:headquarterAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx:legalAddress\": {\n      \"gx:countrySubdivisionCode\": \"BE-BRU\"\n    },\n    \"gx-terms-and-conditions:gaiaxTermsAndConditions\": \"70c1d713215f95191a11d38fe2341faed27d19e083917bc8732ca4fea4976700\"\n  },\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-29T16:05:10Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..fqGrFQqR2LrwQ3j2IC5QPZAHsTNIcfDDe8AjgGOzvY5yOKCj4VDE0rSpb70dQIwoGKJEDEQFUQnEXXlKDZSD79EmSDdJJTpTJJ4xlAS8kXHc6jEgq0gYKkKY7eTUQUhuHrCGFEJ-I-KTJLut3czcdzsRsBITqDbazrEoFOvgKv_C6XzOYIMWxxcczRtGFkKm8c-lIHayABnfHV9ES6PsfwNBuGC5HcsCY0lUZ9h4PMMYC60p-sspCxKLzpILfpcGLV-D73JGrvLycdW7zYNW_M5IQ0gOhaebw_oNSfSdaX08QZ9fAQhXLg3QzX4qIvLzsQVVmn1XFbXdiye574x89w\"\n  }\n\n```\n\n## Verify a participant self-description\n\nThis command verifies a participant self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the participant self-description is compliant.\n\nThe optional `---show` option shows the contents of credential on the console\n\n```shell\ngx-agent participant sd verify -id dff1ffbee0abd14c9483946dbe703d443702a7bdbc5b74dce5d29f3e8afb0c197698656d5d1466726c6e57b9ed0590befbf650f09e4a5552999a8697ef511143\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ verified │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Ecosystems\n\nUp until now the commands have interacted with the Gaia-X compliance service. The participant self-description resulted\nin a Compliance credential being issued by the Compliance Server. You will find the concept of self-descriptions in\nlater chapters. These self-descriptions are being used by participants in specific ecosystems. 'The Future Mobility\nAlliance' is one such ecosystem. The Gaia-X agent supports adding new ecosystems, as long as they are using endpoints\nsimilar to the compliance server.\n\n## Add an ecosystem\n\nAdds a new ecosystem to the `agent.yml` file. The name and url are required arguments. If the name contains any spaces\nbe sure to add quotes (\") around the name. We suggest to keep the name short and succinct, maybe even abbreviating the\nfull name of the ecosystem. You can always provide an optional description, containing the full name.\n\n```shell\ngx-agent ecosystem add FMA https://compliance.future-mobility-alliance.org -d \"Future Mobility Alliance\"\n\noutput:\nNew ecosystem FMA has been added to your agent configuration: C:\\Users\\Example\\.gx-agent\\agent.yml\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n## Update an ecosystem\n\nIf you made a mistake in the url or description, you of course could delete the ecosystem first and then add it again,\nbut there is also an update command. Actually that command is an alias for the add command. The command looks at whether\nan existing ecosystem is already found by that name. If so it updates it.\nIf you made a mistake in the name, you will have to delete the erroneous ecosystem by name and add the new one\n\n## Delete an ecosystem\n\nBe aware that if you delete an ecosystem you will not be able to interact with it again, unless you re-add it of-course.\n\n```shell\ngx-agent ecosystem delete FMA\n\n output:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\nEcosystem FMA has been deleted from your agent configuration: C:\\Users\\example\\.gx-agent\\agent.yml\n```\n\n## List\n\nYou can list all known ecosystems from the `agent.yml` configuration file using the below command.\n\n```shell\ngx-agent ecosystem list\n\noutput:\n┌──────┬─────────────────────────────────────────────────┬──────────────────────────┐\n│ name │                                             url │              description │\n├──────┼─────────────────────────────────────────────────┼──────────────────────────┤\n│  FMA │ https://compliance.future-mobility-alliance.org │ Future Mobility Alliance │\n└──────┴─────────────────────────────────────────────────┴──────────────────────────┘\n```\n\n# Service Offerings\n\nAs soon as you are a Gaia-X compliant participant, you can start to offer services. In order to do so, you first need to\ncreate a service offering self-description. This is a so called \"Credential\". You will need to sign this self-description, using\nyour DID, making it a Verifiable Credential. The compliance service will issue an attestation, in the form of a\nServiceOffering Credential, signed by it’s DID. This allows you to prove to others that you provide certain services.\n\n## Export example service-input-credential.json\n\nThere is a command to export a template/example service-offering self-description to disk. You can then edit this example\nself-description with your information.\nWe currently support creation of two different version of this entity. If you want to create the latest version, you have to provide a type argument as well. Accepted type for a service-offering are mentioned below (also you can see them with passing a `-h` to export-example command):\nIn the current version you can create an example with calling agent:\n\n_The ServiceOffering and it's example might change in the near future as GAIA-X team are modifying this part_\n\n```shell\n┌────────────────────────────────┬\n│             type               │\n├────────────────────────────────┤\n│ gx_ServiceOffering             │\n├────────────────────────────────┤\n│ DcatDataService                │\n├────────────────────────────────┤\n│ DcatDataset                    │\n└────────────────────────────────┴\n```\n\nThe `--show` argument, displays the example self-description to your console.\n\n```shell\n\ngx-agent so sd example -d did:web:nk-gx-agent.eu.ngrok.io\n\noutput:\nIMPORTANT: the values specified with '*' should be populated by you.\n┌──────────────────┬────────────────────────────────────────┬────────────────────────────────────────────────┐\n│             type │                                sd-file │                                            did │\n├──────────────────┼────────────────────────────────────────┼────────────────────────────────────────────────┤\n│ service-offering │ service-offering-input-credential.json │ did:web:nk-gx-agent.eu.ngrok.io                │\n└──────────────────┴────────────────────────────────────────┴────────────────────────────────────────────────┘\nExample service-offering self-description file has been written to service-offering-input-credential.json. Please adjust the contents and use one of the onboarding methods\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu/development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"urn:uuid:b0aee1c5-a00f-46b4-8142-dbe60903f8b2\",\n  \"credentialSubject\": {\n    \"id\": \"https://nk-gx-agent.eu.ngrok.io\",\n    \"type\": \"gx:ServiceOffering\",\n    \"gx:providedBy\": {\n      \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\"\n    },\n    \"gx:policy\": \"\",\n    \"gx:termsAndConditions\": {\n      \"gx:URL\": \"http://termsandconds.com\",\n      \"gx:hash\": \"d8402a23de560f5ab34b22d1a142feb9e13b3143\"\n    },\n    \"gx:dataAccountExport\": {\n      \"gx:requestType\": \"API\",\n      \"gx:accessType\": \"digital\",\n      \"gx:formatType\": \"application/json\"\n    }\n  },\n  \"type\": \"VerifiableCredential\"\n}\n\n```\n\nYou now should open the file, and adjust the values with your service-offer information. Update all\nthe values. Make sure to save the file afterwards. If you made some mistakes, you can always re-export the example. Be\naware that it\nwill always overwrite the existing file!\n\n## Submit the service-offering self-description\n\nThe next command creates a self-asserted Verifiable Credential out of the ServiceOffering self-description input file.\n\n```shell\ngx-agent so sd submit -sof service-offering-input-credential.json -sid <id>\n```\n\nFor the id, see \"gx-agent vc list\"\nIt sends that in\nas a Verifiable Presentation with previously fetched ComplianceCredential and Participant SelfDescription to the Ecosystem Compliance service as configured in your agent.yml file.\n\n```json\n{\n  \"type\": [\"VerifiablePresentation\"],\n  \"@context\": [\"https://www.w3.org/2018/credentials/v1\"],\n  \"verifiableCredential\": [\n    { // Your LegalParticipant self-description VerifiableCredential },\n    { // Your ServiceOffering self-description  VerifiableCredential },\n    { // Your LegalParticipant Compliance Credential Signed by Gaia-X Compliance service },\n  ],\n  \"holder\": \"did:web:4c30-2001-1c04-2b10-ee00-e7d5-abed-7e72-9d92.ngrok-free.app\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-06-01T08:47:10Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..h-rEB7ZPqRCh4Pb9eXK7iX4PEtwF9GdHlrrMR6JSnybVMsxnKcN5tBgqJx33dSIXyPtPSciA2rcp2d7qyQ_tr60oD2dMwu2xnYqgRL67iIkGfg8jIRpunjrZG2PQXPK61ziZvGo4HwuVztY5bwZAqtGTKRs7dWona3U7q2uGsELHojFoHIHfR_j0RPSxLWh8ek_8ZNE13aNVR9QvPwUcxEJ9OGhifhO6XVwwFUDtNtgbGqIU4mwdSC6DU2h6yUsYSK2pu7SRj7qrq4cDbp70OAuLwV8Sywg5IqxuJKKlJZq5YJy_7hgBSvr3RcqeY8BSFr7-H2QGg2n9HuWRIKuwNg\"\n  }\n}\n```\n\nAnd you Ecosystem Compliance Service will send you another ComplianceCredential in response:\n\n```json\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.lab.gaia-x.eu//development/api/trusted-shape-registry/v1/shapes/jsonld/trustframework#\"\n  ],\n  \"type\": [\"VerifiableCredential\"],\n  \"id\": \"https://nk-eco-compliance.eu.ngrok.io/credential-offers/67645d91-6bb5-4661-a6d1-2d36dce30172\",\n  \"issuer\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n  \"issuanceDate\": \"2023-05-31T14:10:01.794Z\",\n  \"expirationDate\": \"2023-08-29T14:10:01.794Z\",\n  \"credentialSubject\": [\n    {\n      \"type\": \"gx:compliance\",\n      \"id\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n      \"integrity\": \"sha256-d03feb54fedcb3ed0411f723bdd8b19e928d742a49f4c7ca109979e08ac83974\"\n    },\n    {\n      \"type\": \"gx:compliance\",\n      \"id\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n      \"integrity\": \"sha256-198332fad39100e726dcc94bd1c68dfbee2db02befc12c92e35e7648b4399336\"\n    },\n    {\n      \"type\": \"gx:compliance\",\n      \"id\": \"did:web:nk-eco-compliance.eu.ngrok.io\",\n      \"integrity\": \"sha256-11fb3ded1ce29b06c5ad15f2bcc8bf1eac41973e70289bf41600aeb1dffe5356\"\n    }\n  ],\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-05-31T14:10:02.314Z\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJQUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..AbRrpo2qbgaCS6HAykU6PACi37iFxlviyu2hxrfhhjhvmz7sItIPFMQc_fj-qGyXD6Zr_LoA2aR5kFE2w4zgu0oEP8Mmudf4fTKzl-3vPNY9lfEUf9tLg_LxLzivs24C2Vz4y2--r2BkNeeXTJ7_pnlBWuDoVPNm3gcrfcT69VcLWmZpErOqhbHTmqafoklr4iGOs7ehU9TGxXS7JptGglAZ_caBVfHvIQQi1MP31mQeIJk7U_t7KohW4Y5ZQKjBL36OL2OqPprZhBEcouOGqI82fRKxAdq22AIjFkgarg9QavwLlq1F_F0qxshpR_QGBE55LV9uU6NJ877Is2sa_w\",\n    \"verificationMethod\": \"did:web:nk-eco-compliance.eu.ngrok.io#JWK2020-RSA\"\n  }\n}\n```\n\n_NOTE: you can run gx-agent vc list in any step and see your VCs in the agent. at the end of this step you should see this list containing all the necessary credentials:_\n\n```shell\n┌─────────────────────┬───────────────────────────────────────┬─────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────┐\n│               types │                                issuer │                         subject │            issuance-date │                                                               id │\n├─────────────────────┼───────────────────────────────────────┼─────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────┤\n│ gx:LegalParticipant │ did:web:nk-gx-agent.eu.ngrok.io       │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T13:08:29.888Z │ <participant sd id>                                              │\n│ ServiceOffering     │ did:web:nk-gx-agent.eu.ngrok.io       │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T13:08:29.888Z │ <service offering sd id>                                         │\n│          Compliance │ did:web:nk-gx-compliance.eu.ngrok.io  │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T14:10:52.037Z │ <participant compliance id from gx-compliance>                   │\n│          Compliance │ did:web:nk-eco-compliance.eu.ngrok.io │ did:web:nk-gx-agent.eu.ngrok.io │ 2023-06-08T14:26:49.870Z │ <participant and service offering compliance from eco-compliance>│\n└─────────────────────┴───────────────────────────────────────┴─────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────┘\n\n```\n\n## List service-offering self-description credentials\n\nYou can list service-offering self-descriptions known to the agent.\n\n```shell\ngx-agent so sd list\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┬──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┐\n│                          issuer │                              subject │            issuance-data │                                                                                                                               id │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┼──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │ 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447 │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┴──────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────────┘\n```\n\n## Show a service-offering self-description credential\n\nTo show the content of a service-offering self-description credential known to the agent, you can first list all the\nservice-offering self-descriptions (see command above). From that output you can get the id value and use that to show\nthe\ncredential.\n\n```shell\ngx-agent so sd show 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\n┌─────────────────────────────────┬──────────────────────────────────────┬──────────────────────────┐\n│                          issuer │                              subject │            issuance-data │\n├─────────────────────────────────┼──────────────────────────────────────┼──────────────────────────┤\n│ did:web:nk-gx-agent.eu.ngrok.io │ 51d15354-4570-4b44-9beb-8e78b9ab6795 │ 2023-01-26T03:35:50.574Z │\n└─────────────────────────────────┴──────────────────────────────────────┴──────────────────────────┘\nid: 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n{\n  \"@context\": [\n    \"https://www.w3.org/2018/credentials/v1\",\n    \"https://registry.gaia-x.eu/v2206/api/shape\"\n  ],\n  \"issuer\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n  \"id\": \"51d15354-4570-4b44-9beb-8e78b9ab6795\",\n  \"credentialSubject\": {\n    \"id\": \"did:web:nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:providedBy\": \"https://nk-gx-agent.eu.ngrok.io/.well-known/participant.json\",\n    \"gx-service-offering:name\": \"my awesome service\",\n    \"gx-service-offering:description\": \"a service by https://nk-gx-agent.eu.ngrok.io\",\n    \"gx-service-offering:termsAndConditions\": [\n      {\n        \"gx-service-offering:url\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\",\n        \"gx-service-offering:hash\": \"myrandomhash\"\n      }\n    ],\n    \"gx-service-offering:gdpr\": [\n      {\n        \"gx-service-offering:imprint\": \"https://nk-gx-agent.eu.ngrok.io/terms-and-conditions/\"\n      },\n      {\n        \"gx-service-offering:privacyPolicy\": \"https://nk-gx-agent.eu.ngrok.io/personal-data-protection/\"\n      }\n    ],\n    \"gx-service-offering:dataExport\": {\n      \"gx-service-offering:requestType\": \"email\",\n      \"gx-service-offering:accessType\": \"digital\",\n      \"gx-service-offering:formatType\": \"mime/png\"\n    }\n  },\n  \"type\": [\n    \"VerifiableCredential\",\n    \"ServiceOffering\"\n  ],\n  \"issuanceDate\": \"2023-01-26T03:35:50.574Z\",\n  \"proof\": {\n    \"type\": \"JsonWebSignature2020\",\n    \"created\": \"2023-01-26T03:35:50Z\",\n    \"verificationMethod\": \"did:web:nk-gx-agent.eu.ngrok.io#JWK2020-RSA\",\n    \"proofPurpose\": \"assertionMethod\",\n    \"jws\": \"eyJhbGciOiJSUzI1NiIsImI2NCI6ZmFsc2UsImNyaXQiOlsiYjY0Il19..UM74Ij3DEv8qRmfMUoJ8wlbJHFA0XOUD8_xl_rYRzxaQvUOtrwgCrCnUyPy3U1JOT8nGnkakbfpT8r2x51T2c8wKUtxynDmtVhmBCfTJdp7fOsM1JC4BKQmAPRHXBUEpgUbLQc60OREyp37uJFzmN66q-blCvEt5v-YHhhnpMO49SUXWMKhhBruEPlPQh6UkfW5SDb9MB\nZcR-INzqQKkBKMDhLkxl4cXpOEepT6fYm-DUq4LVaGCy3NHdB6SNF7asNT0xIHXSX5UiU-ZeQsz0Q1O8tSuhvk2NP0IFy4RXO6IIynP56RPeY05CbW40ejE65TNCzyc2xNyU0CZFcWy3Q\"\n  }\n}\n\n```\n\n## Verify a service-offering self-description\n\nThis command verifies a service-offering self-description credential. It first does a local validation of the Verifiable\nCredential, including a check on the signature/proof. After that it contacts the compliance service to check whether the\ncompliance service provides a response that the service-offering self-description is compliant.\n\nThe optional `--show` option shows the contents of credential on the console\n\n```shell\ngx-agent so sd verify -id 98021d8c32ccf3723ecf83d712a634000ecf10875e1e9b39ece5f90606f65227959936269ad0d65ed9921b6062d9d4cd3ba2ea8d441e38f748e758c864942447\n\noutput:\nAgent validation of the self-description. Valid: true\n┌──────────┐\n│ conforms │\n├──────────┤\n│     true │\n└──────────┘\n```\n\n# Labels\n\nUsing this agent, you can also create all kinds of Labels as well. You can then include these labels in your Service Offerings to show a certain credential. Here is an example for a ISO VerifiableCredential:\nFirst, you need to create a VerifiableCredential (or ask a third party to generate a VerifiableCredential for you). In order to do this with this agent, you can simply call the following command on an _unsigned credential_\n\n```shell\ngx-agent vc issue -f ./iso.json -p\n```\n\nAfter acquiring a Label Verifiable Credential, you can include this label into you Service Offering VerifiablePresentations. You can use this for both onboarding a Service Offering into gx-compliance and also your selected ecosystem:\nFor onboarding the service in the **ecosystem**:\n\n```shell\ngx-agent ecosystem so submit FMA -sid <you self-description participant vc id> -cid <your gx compliance credential id> -eid <your ecosystem compliance id> -sof ./service-offering-input-credential.json -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\nFor onboarding the service in the **gx compliance**:\n\n```shell\ngx-agent so sd submit -sof ./service-offering-input-credential.json -sid <ID of your participant self-description vc> -cid <ID of your compliance VC from Gaia-X compliance> -lai <your label id(s)>\n# you can also call pass the labels via the file using laf (`--label-files`) instead of `lai` parameter\n```\n\n# Developers\n\n## Building an executable\n\nMake sure the CLI is build as well as it dependencies in this monorepo, eg `yarn build`\nAlso install the [pkg]() progam, globally, eg `yarn global add pkg`\n\nNow create the binaries for the different platforms:\n\n```shell\npkg ./dist/cli.js\n```\n","readmeFilename":"README.md"}