chainctl
chainctl Chainguard Control
For the complete documentation index, see llms.txt.
Create a delegate: an identity that acts only on grants you mint for it.
Create a delegate: an identity that acts only on grants you mint for it.
A delegate holds no role bindings and cannot be assumed directly. Its only use is the delegated exchange of a grant minted by its subject with “chainctl auth token –delegate=NAME”. The exchanged token’s subject is the delegate, it records you as the actor, and it carries at most the grant’s capabilities within the delegate’s organization.
The delegate pins your identity as its subject (or –subject, which requires permission to create identities), this environment’s issuer, and a randomly generated delegation audience that grants for it are minted for.
Grants are stateless, so there is no per-grant list or revoke. Deleting the delegate stops every future exchange; grants already minted for it expire within 60 minutes.
chainctl iam identities create delegate NAME [--parent=PARENT] [--description=DESC] [--subject=IDENTITY_ID] [--yes] [--output=id|json|table] # Create a delegate in an organization and mint a grant for it.
chainctl iam identities create delegate my-delegate --parent=my-org
chainctl auth token --delegate=my-delegate --role=viewer --scope=ORGANIZATION_ID
# As an administrator, create a delegate for another user.
chainctl iam identities create delegate their-delegate --parent=my-org --subject=IDENTITY_ID -d, --description string The description of the resource.
-n, --name string Given name of the resource.
--parent string The name or id of the parent location to create this identity under. Defaults to the default.group config value (env: CHAINGUARD_DEFAULT_GROUP).
--subject string The Chainguard identity ID allowed to mint grants for this delegate (default: your own).
-y, --yes Automatic yes to prompts; assume "yes" as answer to all prompts and run non-interactively. --api string The url of the Chainguard platform API. (default "https://console-api.enforce.dev")
--audience string The Chainguard token audience to request. (default "https://console-api.enforce.dev")
--config string A specific chainctl config file. Uses CHAINCTL_CONFIG environment variable if a file is not passed explicitly.
--console string The url of the Chainguard platform Console. (default "https://console.chainguard.dev")
--force-color Force color output even when stdout is not a TTY.
-h, --help Help for chainctl
--issuer string The url of the Chainguard STS endpoint. (default "https://issuer.enforce.dev")
--log-level string Set the log level (debug, info) (default "ERROR")
-o, --output string Output format. One of: [csv, env, go-template, id, json, markdown, none, table, terse, tree, wide]
-v, --v int Set the log verbosity level.Last updated: 2026-09-30 19:15