Every command of the bundle is prefixed beffroi:, and each one acts on the tenant the configuration
names. A command that reads is never the command that writes: beffroi:user:show reads,
beffroi:user:profile writes, and they are two classes.
Run bin/console beffroi:<group>:<command> --help for the arguments and the options of one of them; the
table below is the map.
List the applications a user agreed to, with what each one holds of them and what it has asked that is still waiting.
beffroi:user:create
Create a user of the tenant; give them a password with beffroi:user:set-password.
beffroi:user:link
Say that a user of the tenant is a given subject at an upstream provider; run again to refresh it.
beffroi:user:profile
Describe a user with the standard claims of OIDC Core section 5.1; what is not said is cleared, a run that says nothing writes nothing. To read a user, see beffroi:user:show.
beffroi:user:revoke-consent
Take back the consent a user gave a client, and the access it holds; the next authorization request asks again.
beffroi:user:revoke-credential
Revoke a credential of a user by its identifier; the credential stays listed as revoked.
beffroi:user:revoke-session
End a session of a user by its identifier; the relying parties of that session are told by the back-channel.
beffroi:user:sessions
List the sessions open in the name of a user, with what each one proved and where it was last seen.
beffroi:user:set-password
Set or replace the password of a user, asked on the terminal or read from the standard input.
beffroi:user:show
Show a user: the identity, the standard claims that are set, and the credentials with their kind, identifier, name and dates.
Make a staged key the active one of its algorithm before its staging delay elapsed; the key it takes over from starts retiring.
beffroi:keys:generate
Generate a key, seal it with the configured KMS and make it the active one of its algorithm at once; "beffroi:keys:rotate" is the rotation without an outage.
beffroi:keys:list
List the keys of the tenant with their use, status and dates: the published ones, or every key with --all; --check opens the keys in use, or about to be, with the KMS and fails on one it cannot open.
beffroi:keys:retire
Take a retiring key out of the JWK Set: one key by its identifier, before its retirement date with --force; or every key past its date with --due.
beffroi:keys:rotate
Stage a new key, sealed by the configured KMS and published at once; it takes over once the staging delay elapsed, or at once with --now; --compromised retires the previous key with no window.
Erase the data keys of the tenant, which makes every personal datum it had sealed unreadable for good. Asks for the slug to be typed back. Cannot be undone.
beffroi:data-keys:list
List the data keys of the tenant by scope, with when each was minted, the master key that wraps it and the KMS client that opens it; reads only, and never opens a key.
beffroi:data-keys:rewrap
Wrap the data keys of the tenant with another KMS client from now on, or with another master key of the same one; --dry-run lists what would move. No sealed value is read or rewritten.
Store a metadata statement file (unsigned, trusted as the file is) next to the FIDO Metadata BLOB, for the keys of a manufacturer the service does not list or the authenticators of the FIDO conformance tools.
beffroi:webauthn:mds-refresh
Download the FIDO Metadata BLOB, verify its signature under the pinned root and store it for the passkey ceremonies; --url for another service, --root for another root.
A command never bypasses a rule the protocol applies. It cannot mint a token for a user, cannot read a
signing key it is not allowed to open, and cannot read a personal datum the key management service refuses
to unseal. beffroi:data-keys:destroy is the one that cannot be undone, and it asks for the slug of the
tenant to be typed back before it runs.