#!/usr/bin/env node /** * bin/olp-keys.mjs — OLP key management CLI (Phase 2 / D47) * * Authority: ADR 0007 § 9 (Bootstrap & recovery — minimal keygen command * surface) + § 10 acceptance criterion #9 (bootstrap workflow must be * reproducible without manual file editing). * * Subcommands: * keygen create a new OLP key; prints plaintext token to stdout ONCE * list list all keys (manifests with token_hash redacted) * revoke mark a key as revoked (idempotent; manifest stays for audit) * * Usage: * olp-keys keygen --owner [--name=