@quantpass/cli
v1.1.0
Published
QuantPass CLI — post-quantum credential management
Readme
Quantlyx CLI
Post-quantum credential management from the terminal.
Installation
# From the monorepo
pnpm install
pnpm --filter @quantpass/cli build
# Link globally
npm link packages/cli
# Or install directly (once published)
npm install -g @quantpass/cliQuick start
# View all available commands and options
qlx --help
# Authenticate (registers a Dilithium2 keypair on first run)
qlx auth login
# Check status
qlx auth status
# List vaults
qlx vault list
# Store a credential
qlx vault store github.com
# Retrieve a credential
qlx vault get github.com
# List credentials (metadata only)
qlx vault items
# List machine secrets
qlx secrets list
# Show current user
qlx whoamiCommands
qlx auth
| Command | Description |
|---|---|
| auth login | Authenticate with Dilithium2 ZK challenge |
| auth logout | Clear local session |
| auth status | Show authentication status |
qlx vault
| Command | Description |
|---|---|
| vault list | List all vaults |
| vault get <domain> | Retrieve a stored credential |
| vault store <domain> | Store a credential |
| vault items | List credential metadata |
qlx secrets
| Command | Description |
|---|---|
| secrets list | List machine credentials |
| secrets get <name> | Get a machine secret |
qlx config
| Command | Description |
|---|---|
| config get [key] | Show config value(s) |
| config set <key> <value> | Set apiUrl or other config |
Configuration
Config is stored at ~/.quantlyx/config.json.
Identities (Dilithium2 keypairs) are stored at ~/.quantlyx/identities.json.
If you have an existing ~/.quantpass/ directory from before this rename, it's migrated automatically and transparently the first time you run any qlx command — your existing login session and saved identities carry over, nothing is lost.
# Point to a different API
qlx config set apiUrl https://your-api.example.comSecurity
- Keypairs are generated locally using ML-DSA-44 (Dilithium2)
- Private keys never leave
~/.quantlyx/identities.json - Authentication uses ZK challenge-response — no password sent over the wire
- Credentials are encrypted server-side with AES-256-GCM + HKDF-SHA256
- FIPS 203/204 compliant
