deed
Identity is Drift's fourth pillar. Its primitives (KeyAuth, JWT, Vault, Link, Pocket) are used from the SDK, not the CLI, so the CLI surface here is read-only by design: there is no command that mints a token or writes an identity, because doing so from a terminal would put authority somewhere the slice cannot verify. Every command below is an inspection, and every value that could reveal a secret is left out rather than shown.
| Command | Description |
|---|---|
drift deed status | Deed resource usage on the active slice: Vault entries, Link identities, Pocket items |
drift deed vault list | List the uids that have written a Vault entry |
drift deed vault get <uid> | Show one uid's current Vault blob |
drift deed link list | List the identities that have a device registry |
drift deed link get <identity> | Show the devices enrolled for one identity |
drift deed pocket list <identity> | List the Pocket key names stored for one identity |
status gives one line each for Vault, Link and Pocket, the quickest way to see whether Deed is holding anything at all; the commands below it are what to reach for once it says yes.
Vault
Vault is an account-key-wrapped keyring: list names only the uids that have written an entry, never the stored values, and get returns one uid's blob. The blob is client-encrypted before it ever reaches Drift, so what prints is the ciphertext the customer's own application stored, not anything this platform can read. Vault is append-only, so get returns the newest entry a uid has written, not its whole history.
Link
Link tracks which devices act for an identity. list names only the identities that have completed a device enrollment, that is, where a second device has actually been attested; an identity with no such history still has exactly one implicit active device (its own account pubkey) and is not in that list. get <identity> reports that implicit device honestly rather than as an empty result, and includes revoked devices alongside active ones.
Pocket is an identity's end-to-end encrypted app data. list <identity> names the key names stored for that identity, never the values: Pocket payloads are encrypted client-side and the slice holds no key that could open them. An identity that has stored nothing and one that does not exist look identical here, since Pocket creates the storage on its first write.
The Deed guide explains what each primitive is for, and Authentication walks a login end to end.