Skip to content
Tenzro
Documentation menu
Build and operate

CLI reference

Install the tenzro CLI and use it to join Network 1, manage keys and identity, run inference, operate a node and call any RPC method.

The tenzro CLI is one binary for everyone on the network. Developers use it to create a passkey account, chat with models and call any JSON-RPC method. Operators use it to set up a node, bond for a role, serve models and issue API keys. Every command talks to a node over JSON-RPC, and every command has --help with the full option list.

Install

bash
# Homebrew (macOS and Linux)
brew tap tenzro/tap && brew install tenzro

# From source with Cargo
cargo install --git https://github.com/tenzro/tenzro-network --bin tenzro

Pre-built binaries for Linux and macOS, including tenzro-node, are on the downloads page.

Check the install:

bash
tenzro version
tenzro info --rpc https://rpc.tenzro.xyz

Global options and endpoints

OptionMeaning
--format text or --format jsonHuman-readable output (default) or JSON for scripts
-v, --verboseVerbose logging
--rpc <url>Node to talk to. Most commands default to your local node at http://127.0.0.1:8545; pass --rpc https://rpc.tenzro.xyz to use the public endpoint. tenzro join defaults to the public endpoint.

Credentials come from flags or the environment: TENZRO_API_KEY (sent as X-Tenzro-Api-Key), TENZRO_ADMIN_TOKEN (sent as X-Tenzro-Admin-Token, operator only) and TENZRO_DATA_DIR for the node data directory.

Join the network

bash
# Guided setup: consume, provide or validate on Network 1,
# bootstrap a local network, or join a private one
tenzro setup

# The same, non-interactive
tenzro setup --path network --mode provide --roles ai,storage --yes
tenzro setup --path local --network-name lab --yes
tenzro setup --path private --genesis ./genesis.toml --bootstrap <multiaddr>

# One-step participation as a user, or as an inference provider
tenzro join --name "Ada"
tenzro join --provider

tenzro setup flags: --path network|local|private, --mode consume|provide|validate, --roles, --operator self|autonomous (autonomous operation requires a TPM 2.0 or Secure Enclave), --access on-demand,subscription,rental, --visibility public|private, --yes.

tenzro join --provider detects your hardware, posts the compute bond, registers you as a provider, sets default pricing and serves the largest catalog model that fits your machine.

Keys, identity and accounts

Keys are hardware-rooted. There are no key files or seed phrases to manage.

bash
tenzro passkey login               # create a passkey account in the browser
tenzro passkey add                 # link another passkey to the account
tenzro passkey list --account-address <address>
tenzro passkey add-guardian ...    # add a recovery guardian
tenzro passkey initiate-recovery ...
tenzro passkey sign ...            # approve an operation hash with your passkey
tenzro passkey grant-session-key ...
tenzro passkey set-spending-limit ...

tenzro identity ...                # register, resolve and inspect DIDs
tenzro device list                 # devices bound to an identity
tenzro device revoke ...           # unbind a device and end its sessions
tenzro auth ...                    # OAuth 2.1 + DPoP tokens for agents
tenzro set-username <name>
tenzro siwt ...                    # Sign-In With Tenzro

See Console and passkey wallet and Device linking and recovery.

Wallet

bash
tenzro wallet balance --address 0x... --rpc https://rpc.tenzro.xyz
tenzro wallet send <to> <amount>            # TNZO by default; --asset for stablecoins
tenzro wallet history 0x... --limit 20
tenzro wallet token-balance ...

Transfers are signed by your account's hardware-rooted key before they reach the network.

AI

bash
tenzro chat                                   # interactive chat, pick a model
tenzro chat <model-id> --max-tokens 512
tenzro chat --use-case code --budget <wei>    # let the router choose a model
tenzro chat <model-id> --jurisdiction DE,EU --require-jurisdiction-receipt

tenzro model list
tenzro model info <model-id>
tenzro model get-hash <model-id>              # published weight hashes
tenzro inference ...

tenzro forecast ...        tenzro embed-text ...     tenzro embed-image ...
tenzro segment ...         tenzro detect ...         tenzro transcribe ...
tenzro media-gen ...       tenzro train ...          tenzro moe ...

--jurisdiction pins a request to serving nodes that declare a matching attested location; with --require-jurisdiction-receipt the request fails unless the response carries a signed jurisdiction receipt. See Inference.

Agents and marketplaces

bash
tenzro agent ...           # register, send, spawn, run tasks, swarms
tenzro memory ...          # per-agent memory: grant, recall, archive, list
tenzro task ...            # task marketplace: post, quote, assign, complete
tenzro marketplace ...     # agent templates
tenzro skill ...           tenzro tool ...          tenzro mcp ...
tenzro cortex ...          tenzro approval ...      # approvals for delegated agents
tenzro erc8004 ...         # agent registry and reputation

Payments and settlement

bash
tenzro payment ...         # challenges and payments over MPP, x402 or TNZO
tenzro x402 list-schemes
tenzro ap2 ...             # mandate verification
tenzro escrow ...          # escrow and payment channels
tenzro rails list          # settlement rails, cheapest first
tenzro rails route ...     # which rail a given charge would take
tenzro bond ...            # agent bonds
tenzro interaction ...     # read and verify interaction receipts

Storage, data and hosting

bash
tenzro files upload ./report.pdf     tenzro files list     tenzro files usage
tenzro database ...                  # create, query, scale, issue connections
tenzro site ...                      # static sites
tenzro function ...                  # wasi:http functions
tenzro machine ...                   # microVM machines
tenzro lease ...                     # hosting leases
tenzro shell login                   # sign in to hardware you rented, with your passkey

Run a node

bash
tenzro node start ...                tenzro node status
tenzro node peers                    tenzro node syncing
tenzro node did-document             # every way to reach this node, in one document
tenzro status                        # live resource and traffic status
tenzro hardware                      # hardware profile
tenzro discover ...                  tenzro cluster ...    # LAN peers and clusters
tenzro visibility show|hide|publish  # what this node advertises

tenzro stake deposit <amount> --provider-type validator|rpc|tee|model|compute|storage|cloud|trainer|syncer
tenzro stake withdraw ...            tenzro stake info ...
tenzro validator register ...        tenzro validator list-active
tenzro provider pricing set ...      tenzro provider bond post ...
tenzro schedule ...                  # when your hardware is available
tenzro model download <model-id>
tenzro model serve <model-id> [--gated | --private]
tenzro tee detect
tenzro tee attest --provider auto|tdx|sev-snp|nitro|gpu

Commands that change your node's policy (pricing, schedules, model lifecycle, bonds) are admin commands and need your node's TENZRO_ADMIN_TOKEN. See Deployment and Operators and roles.

Access control on your node

bash
tenzro admin api-key create --label acme --subject did:tenzro:human:... \
  --scope inference --scope storage --tier standard
tenzro admin api-key list
tenzro admin api-key revoke --key-id <key-id>

tenzro admin service-key add --key "$(openssl rand -hex 32)"
tenzro admin service-key status
tenzro admin service-key revoke --key-digest <sha256-hex>

tenzro shell lease open ...          tenzro shell lease list     tenzro shell lease revoke ...

# for the holder of an API key
tenzro key list-mine
tenzro key revoke-mine --key-id <key-id>

See API keys and RPC access.

Call any method

bash
tenzro rpc methods --contains database --rpc https://rpc.tenzro.xyz
tenzro rpc methods --namespaces
tenzro rpc call tenzro_getSupplyMetrics --rpc https://rpc.tenzro.xyz
tenzro rpc call tenzro_getBlock --params '{"height":"latest"}'

tenzro rpc methods prints each method with its access class and, where one applies, the API-key scope it needs. tenzro rpc call accepts --api-key and --admin-token for methods that need them.

Chain, interop and governance

bash
tenzro contract ...        tenzro token ...          tenzro events ...
tenzro governance ...      tenzro zk ...             tenzro vrf ...
tenzro bridge ...          tenzro ccip ...           tenzro wormhole ...
tenzro erc7683 ...         tenzro caip ...           tenzro canton ...

See Multi-VM runtime and Bridge.