Commands

CommandPurpose
denkeeper serveStart the agent
denkeeper versionPrint version information
denkeeper keysManage REST API keys
denkeeper sessionsInspect and prune conversation sessions
denkeeper passwdGenerate a bcrypt hash for dashboard login
denkeeper pluginEd25519 plugin signing

Flags

--config / -c is accepted by the commands that read the config file — serve, keys, and sessions. It is not a root-level flag, so denkeeper --config ... <command> will not work; put it after the subcommand instead.

FlagAvailable onDescription
--config PATH, -cserve, keys, sessionsPath to config file (default: ~/.denkeeper/denkeeper.toml)
--helpall commandsPrint help

There is no --version flag. Use the denkeeper version subcommand.

denkeeper serve

Start the agent. Loads config, connects adapters, starts the scheduler, and optionally starts the REST API server.

denkeeper serve
denkeeper serve --config /etc/denkeeper/denkeeper.toml

denkeeper version

Print the version, commit, build date, Go version, and platform.

denkeeper version

denkeeper keys

Create and list API keys for the REST API and web dashboard.

denkeeper keys create dashboard --scopes admin,chat,sessions:read
denkeeper keys list

denkeeper keys create <name>

The key name is a positional argument, not a flag.

Argument / flagDescription
<name>Key name (required, positional)
--scopes, -sComma-separated list of scopes (default: admin)

The plaintext key is displayed once on creation and cannot be recovered.

denkeeper keys list

Lists all API keys with their names, scopes, status, and creation dates. The key secret is never shown.

Revoking a key

The CLI does not revoke keys — keys only has create and list. Revoke, permanently delete, and rotate through the REST API or the dashboard’s API Keys page:

curl -X DELETE -H "Authorization: Bearer dk_..." \
  https://localhost:8080/api/v1/keys/{id}             # revoke
curl -X DELETE -H "Authorization: Bearer dk_..." \
  https://localhost:8080/api/v1/keys/{id}/permanent   # delete a revoked key
curl -X POST -H "Authorization: Bearer dk_..." \
  https://localhost:8080/api/v1/keys/{id}/rotate      # rotate

denkeeper sessions

Manage conversation sessions stored in the memory database.

denkeeper sessions list

List all sessions with metadata.

denkeeper sessions list
denkeeper sessions list --config /path/to/denkeeper.toml

Displays a table with session ID, adapter, external ID, message count, cost, and creation date.

denkeeper sessions show <session-id>

Display all messages in a session.

denkeeper sessions show "telegram:12345"

Shows each message with timestamp, role, and content (truncated to 120 characters).

denkeeper sessions delete <session-id>

Delete a session and all its messages.

denkeeper sessions delete "telegram:12345"
denkeeper sessions delete "telegram:12345" --yes
FlagDescription
--yes, -ySkip confirmation prompt

denkeeper sessions export <session-id>

Export a session transcript to stdout.

denkeeper sessions export "telegram:12345"
denkeeper sessions export "telegram:12345" --format json > session.json
FlagDescription
--format, -fOutput format: text (default) or json

denkeeper sessions prune

Delete sessions older than a specified duration.

denkeeper sessions prune --older-than 720h
denkeeper sessions prune --older-than 720h --yes
FlagDescription
--older-thanDuration threshold (e.g., 720h for 30 days). Required.
--yes, -ySkip confirmation prompt

denkeeper passwd

Generate a bcrypt hash for dashboard password login.

denkeeper passwd

Reads the password interactively with confirmation. Also accepts piped stdin for scripted use:

echo "my-password" | denkeeper passwd

Outputs a bcrypt hash (cost 13) suitable for the api.auth.password_hash config field.

denkeeper plugin

Manage Ed25519 plugin signing. These commands help you sign and verify plugin binaries for secure distribution.

denkeeper plugin keygen <name>

Generate an Ed25519 key pair for plugin signing.

denkeeper plugin keygen my-plugin
denkeeper plugin keygen my-plugin --output /path/to/keys
FlagDescription
--outputOutput directory for key files (default: current directory)

Creates two files: <name>.pub (public key, PEM) and <name>.key (private key, PEM, mode 0600).

denkeeper plugin sign <binary>

Sign a plugin binary with an Ed25519 private key.

denkeeper plugin sign ./my-plugin --key my-plugin.key
FlagDescription
--keyPath to private key file (required)

Creates a detached signature file <binary>.sig.

denkeeper plugin verify <binary>

Verify a plugin binary’s signature against one or more public keys.

denkeeper plugin verify ./my-plugin --key my-plugin.pub
denkeeper plugin verify ./my-plugin --key key1.pub --key key2.pub
FlagDescription
--keyPath to public key file (required, repeatable)

Exits with code 0 if the signature is valid for any of the provided keys.