drift Docs
Start
What is Drift?
The tour, if you are new here.
Use cases
Whether Drift does your thing.
Getting started
Nothing to deployed, in one command.
Architecture
How a slice is put together.
What it costs
The free grant, four unit prices, two rules.
Build
Canvas
Static sites, same origin as your API.
Tools
Operate
Auth
Route gates, API keys and your account.
Security
Boundaries, sandboxing and hardening.
Troubleshooting
Error codes
What went wrong, and what to do about it.
Legal
Acceptable use
What a slice may not be used for.
Data processing
The DPA, and every sub-processor.

deed

Identity is Drift's fourth pillar. Its primitives (KeyAuth, JWT, Vault, Link, Pocket) are used from the SDK, not the CLI, so the CLI surface here is read-only by design: there is no command that mints a token or writes an identity, because doing so from a terminal would put authority somewhere the slice cannot verify. Every command below is an inspection, and every value that could reveal a secret is left out rather than shown.

Command Description
drift deed statusDeed resource usage on the active slice: Vault entries, Link identities, Pocket items
drift deed vault listList the uids that have written a Vault entry
drift deed vault get <uid>Show one uid's current Vault blob
drift deed link listList the identities that have a device registry
drift deed link get <identity>Show the devices enrolled for one identity
drift deed pocket list <identity>List the Pocket key names stored for one identity

status gives one line each for Vault, Link and Pocket, the quickest way to see whether Deed is holding anything at all; the commands below it are what to reach for once it says yes.

Vault

Vault is an account-key-wrapped keyring: list names only the uids that have written an entry, never the stored values, and get returns one uid's blob. The blob is client-encrypted before it ever reaches Drift, so what prints is the ciphertext the customer's own application stored, not anything this platform can read. Vault is append-only, so get returns the newest entry a uid has written, not its whole history.

Link tracks which devices act for an identity. list names only the identities that have completed a device enrollment, that is, where a second device has actually been attested; an identity with no such history still has exactly one implicit active device (its own account pubkey) and is not in that list. get <identity> reports that implicit device honestly rather than as an empty result, and includes revoked devices alongside active ones.

Pocket

Pocket is an identity's end-to-end encrypted app data. list <identity> names the key names stored for that identity, never the values: Pocket payloads are encrypted client-side and the slice holds no key that could open them. An identity that has stored nothing and one that does not exist look identical here, since Pocket creates the storage on its first write.

The Deed guide explains what each primitive is for, and Authentication walks a login end to end.