The complete command surface of the Loam substrate.
This reference lists:
- every subsystem
- every subcommand
- required/optional arguments
- one-line descriptions
It is mechanical, not conceptual. For architecture and mental models, see the Architecture Overview.
Anywhere the CLI expects a argument, you may supply any of the following:
Human‑friendly name — the name you assigned with identity issue --name or identity name
Store UUID — the directory name under ~/.loam/stores/
Identity fingerprint — the cryptographic fingerprint shown in identity show
All three forms resolve to the same identity store. If a command requires a specific form (rare), it is noted explicitly.
loam <system> <action> [args...]identitylogssecretstateopsrunexec
Issue a new identity store.
loam identity issue [--name <name>] [--plaintext] [--passphrase <pw>]Arguments:
--name— human-friendly name--plaintext— issue unencrypted (insecure)--passphrase— non-interactive encrypted issuance
List all identity stores.
loam identity listShow identity metadata.
loam identity show <store>Verify continuity and store integrity.
loam identity verify <store>Get or set a store’s human-friendly name.
loam identity name <store> [new_name]Rename a store.
loam identity rename <store> <new_name>Revoke an identity by fingerprint.
loam identity revoke <fingerprint> [--note <text>]Remove an identity from the revocation list.
loam identity unrevoke <fingerprint>List all revoked identities.
loam identity revokedEncrypt an existing identity store.
loam identity encrypt <identity>Decrypt an existing identity store.
loam identity decrypt <identity>Unlock an encrypted identity for this session.
loam identity unlock <identity>Lock an identity for this session.
loam identity lock <identity>Lock all identities for this session.
loam identity lock-allShow continuity or chronicle log.
loam logs show <continuity|chronicle> <store>Verify continuity and chronicle logs.
loam logs verify <store>Show continuity and chronicle interwoven.
loam logs interlaced <store>Create a secret.
loam secret create <store> <secret_name> [--value <value>]List secrets.
loam secret list <store>Load a secret (temporary command).
loam secret load <store> <secret_name>Rotate a secret.
loam secret rotate <store> <secret_name> [--value <value>]Delete a secret.
loam secret delete <store> <secret_name>Enable state hashing.
loam state enable <store> [--path <abs-path>]Disable state hashing.
loam state disable <store>Show state hashing status.
loam state show <store>Set a state path without enabling hashing.
loam state set-path <store> --path <abs-path>Remove state path and disable hashing.
loam state unset-path <store>Verify an artifact envelope against an identity’s public key.
loam ops verifyartifact <store> <artifact>Export a sealed identity store.
loam ops export <store> --out <dir> [--passphrase <pw>]Import a sealed identity store.
loam ops import <store-dir> [--passphrase <pw>]loam run [--python-driver] [--legacy-python] <store> <exec_path> [--passphrase <pw>] [args...]loam exec <store> <program> [--passphrase <pw>] [args...]