The CLI is a face, not a toy
The kestrel.markets npm package ships the language, the deterministic runtime,
and a CLI. Some verbs run entirely offline on your machine; four platform verbs —
sim, prove, certify, verify — reach api.kestrel.markets to a shareable
proof URL, free and anonymous. This is a practicum: read
the four faces for the contract; here we thread the
verbs into a workflow you can run right now with npx, no install and no signup.
Run a session and mint a proof
Point sim at a free generic scenario. It runs a deterministic hosted session
over managed data — no wall time, no card — and prints a certified proof URL:
npx kestrel.markets sim fomc-rate-decision-whipsawoperation op_… · completed
evidence manifest=art_… bus=art_… grade=art_…
proof https://kestrel.markets/proof/art_…That proof URL is the durable handle for the run — the same object the other three
faces produce. (prove is the same hosted core behind a zero-credential front
door: npx kestrel.markets prove runs with no key and no config at all.)
Recompute the proof locally, byte for byte
A proof URL is not asking to be believed. certify fetches the proof's evidence
bundle, re-projects the Blotter on your machine with the shipped projector, and
asserts the bytes match the hosted result:
npx kestrel.markets certify https://kestrel.markets/proof/art_f576347572a410a52647cf90REPRODUCED reproduced=true published_blotter=sha256:… local_blotter=sha256:…When the published and local hashes are equal, you have not trusted the server's numbers — you have regenerated them.
Verify a stranger's proof
certify reproduces the computation; verify checks the signature. Point it at
any proof URL — one you did not run, from an account you do not have — and it
re-verifies the Grade's Ed25519 signature against the platform's
independently fetched published keys:
npx kestrel.markets verify https://kestrel.markets/proof/art_f576347572a410a52647cf90VERIFIED proof=art_f576347572a410a52647cf90 kid=ksign-2026-07-prod epoch=1Public keys can check a signature, never create one, so this proves the platform signed exactly this record — and you learned it without trusting the page that served it.
The workflow the four verbs carry
Threaded together, that is the loop: run → prove → recompute → verify a
stranger's. Someone runs a session and shares a proof URL; anyone who holds it
recomputes the record (certify) and re-checks the signature (verify) on their
own machine.
These four verbs reach the hosted funnel to mint and check proof URLs, and the local runtime replays the committed regime tapes offline. For the reference verb-by-verb surface, read the CLI.
See it in kestrel
You have already seen it: the three commands above are the workflow. Keep the capability one command away — drop the kestrel.markets MCP server into your client so the next session opens where this one left off, no account in between.