Commands

CommandPurpose
denkeeper serveStart the agent
denkeeper versionPrint version information
denkeeper keysManage REST API keys
denkeeper sessionsInspect and prune conversation sessions
denkeeper decideCalibrate decision models against recorded supervisor reviews
denkeeper passwdGenerate a bcrypt hash for dashboard login
denkeeper pluginEd25519 plugin signing

Flags

--config / -c is accepted by the commands that read the config file — serve, keys, sessions, and decide. It is not a root-level flag, so denkeeper --config ... <command> will not work; put it after the subcommand instead.

FlagAvailable onDescription
--config PATH, -cserve, keys, sessions, decidePath to config file (default: ~/.denkeeper/denkeeper.toml)
--helpall commandsPrint help

There is no --version flag. Use the denkeeper version subcommand.

denkeeper serve

Start the agent. Loads config, connects adapters, starts the scheduler, and optionally starts the REST API server.

denkeeper serve
denkeeper serve --config /etc/denkeeper/denkeeper.toml

denkeeper version

Print the version, commit, build date, Go version, and platform.

denkeeper version

denkeeper keys

Create and list API keys for the REST API and web dashboard.

denkeeper keys create dashboard --scopes admin,chat,sessions:read
denkeeper keys list

denkeeper keys create <name>

The key name is a positional argument, not a flag.

Argument / flagDescription
<name>Key name (required, positional)
--scopes, -sComma-separated list of scopes (default: admin)

The plaintext key is displayed once on creation and cannot be recovered.

denkeeper keys list

Lists all API keys with their names, scopes, status, and creation dates. The key secret is never shown.

Revoking a key

The CLI does not revoke keys — keys only has create and list. Revoke, permanently delete, and rotate through the REST API or the dashboard’s API Keys page:

curl -X DELETE -H "Authorization: Bearer dk_..." \
  https://localhost:8080/api/v1/keys/{id}             # revoke
curl -X DELETE -H "Authorization: Bearer dk_..." \
  https://localhost:8080/api/v1/keys/{id}/permanent   # delete a revoked key
curl -X POST -H "Authorization: Bearer dk_..." \
  https://localhost:8080/api/v1/keys/{id}/rotate      # rotate

denkeeper sessions

Manage conversation sessions stored in the memory database.

denkeeper sessions list

List all sessions with metadata.

denkeeper sessions list
denkeeper sessions list --config /path/to/denkeeper.toml

Displays a table with session ID, adapter, external ID, message count, cost, and creation date.

denkeeper sessions show <session-id>

Display all messages in a session.

denkeeper sessions show "telegram:12345"

Shows each message with timestamp, role, and content (truncated to 120 characters).

denkeeper sessions delete <session-id>

Delete a session and all its messages.

denkeeper sessions delete "telegram:12345"
denkeeper sessions delete "telegram:12345" --yes
FlagDescription
--yes, -ySkip confirmation prompt

denkeeper sessions export <session-id>

Export a session transcript to stdout.

denkeeper sessions export "telegram:12345"
denkeeper sessions export "telegram:12345" --format json > session.json
FlagDescription
--format, -fOutput format: text (default) or json

denkeeper sessions prune

Delete sessions older than a specified duration.

denkeeper sessions prune --older-than 720h
denkeeper sessions prune --older-than 720h --yes
FlagDescription
--older-thanDuration threshold (e.g., 720h for 30 days). Required.
--yes, -ySkip confirmation prompt

denkeeper decide

Work with the decision models configured under [[llm.deciders]].

denkeeper decide replay

Re-score an agent’s recorded supervisor reviews with a decider and report how often the two agree. Use it to pick supervisor_decider_approve_at and supervisor_decider_deny_at from existing audit history. It is read-only: nothing is written to the audit log and no approval outcome changes.

denkeeper decide replay --agent default
denkeeper decide replay --agent default --since 2026-09-01 --decider jev --limit 200
denkeeper decide replay --agent default --format json > replay.json
FlagDescription
--agentAgent whose supervisor reviews to replay. Required.
--decider[[llm.deciders]] name (default: the agent’s supervisor_decider)
--sinceReplay reviews from this date, 2006-01-02 or RFC3339 (default: 30 days ago)
--approve-at, --deny-atThresholds for the agreement table (default: the agent’s configured values)
--limitMaximum reviews to replay, newest first (default: 500)
--showDisagreements to list (default: 20)
--concurrencyParallel decider calls (default: 4)
--format, -fOutput format: text (default) or json

The report has four parts:

  • Agreement table: the decider’s verdict (approve, escalate, deny) against the supervisor’s, at the chosen thresholds.
  • Threshold sweep: for each approve_at, how many calls the decider would approve and how many of those the supervisor did not; for each deny_at, how many it would deny and how many of those the supervisor approved.
  • Disagreements: decider approvals the supervisor denied or escalated come first, then decider denials the supervisor approved.
  • Latency and cost: p50 and p95 per call, and the total provider-reported cost of the replay.

Two things to know before running it:

  • Egress: each replayed review sends its tool arguments and the recent messages before it to the decider’s provider, and each call is billed.
  • Thinner input than a live review: the audit log does not record the tool description, server guidance, or skill context, and a conversation that was cleared, compacted, or pruned has no user request to recover. Treat replay as indicative. The source = "decider:<name>" audit events written by shadow mode are the authoritative comparison.

Only reviews that ended in a supervisor verdict are replayed. Failed reviews and calls that went straight to a human are not in the set.

denkeeper passwd

Generate a bcrypt hash for dashboard password login.

denkeeper passwd

Reads the password interactively with confirmation. Also accepts piped stdin for scripted use:

echo "my-password" | denkeeper passwd

Outputs a bcrypt hash (cost 13) suitable for the api.auth.password_hash config field.

denkeeper plugin

Manage Ed25519 plugin signing. These commands help you sign and verify plugin binaries for secure distribution.

denkeeper plugin keygen <name>

Generate an Ed25519 key pair for plugin signing.

denkeeper plugin keygen my-plugin
denkeeper plugin keygen my-plugin --output /path/to/keys
FlagDescription
--outputOutput directory for key files (default: current directory)

Creates two files: <name>.pub (public key, PEM) and <name>.key (private key, PEM, mode 0600).

denkeeper plugin sign <binary>

Sign a plugin binary with an Ed25519 private key.

denkeeper plugin sign ./my-plugin --key my-plugin.key
FlagDescription
--keyPath to private key file (required)

Creates a detached signature file <binary>.sig.

denkeeper plugin verify <binary>

Verify a plugin binary’s signature against one or more public keys.

denkeeper plugin verify ./my-plugin --key my-plugin.pub
denkeeper plugin verify ./my-plugin --key key1.pub --key key2.pub
FlagDescription
--keyPath to public key file (required, repeatable)

Exits with code 0 if the signature is valid for any of the provided keys.