Unit 5 of 22 · Intermediate

The desk from a terminal (CLI)

The short version

This is a builder practicum that threads the shipped CLI verbs into one real workflow, run from a terminal against the managed API. You run a free simulation over a generic scenario and mint a certified proof URL; you recompute that proof locally, byte for byte, so you trust the math instead of the server; and you verify a stranger's proof — one you did not run and hold no key for — by re-checking its signature against independently fetched published keys. Four verbs carry the whole loop: sim and prove reach the hosted funnel to a shareable proof URL, free and anonymous; certify re-projects the record on your machine and asserts it is identical; verify re-checks the Ed25519 signature with no trust in the server. Every command shown is one that runs now, with no signup and no card, and the reference CLI surface covers the rest verb by verb.

The CLI is a face, not a toy

The kestrel.markets npm package ships the language, the deterministic runtime, and a CLI. Some verbs run entirely offline on your machine; four platform verbs — sim, prove, certify, verify — reach api.kestrel.markets to a shareable proof URL, free and anonymous. This is a practicum: read the four faces for the contract; here we thread the verbs into a workflow you can run right now with npx, no install and no signup.

Run a session and mint a proof

Point sim at a free generic scenario. It runs a deterministic hosted session over managed data — no wall time, no card — and prints a certified proof URL:

npx kestrel.markets sim fomc-rate-decision-whipsaw
operation  op_… · completed
evidence   manifest=art_… bus=art_… grade=art_…
proof      https://kestrel.markets/proof/art_…

That proof URL is the durable handle for the run — the same object the other three faces produce. (prove is the same hosted core behind a zero-credential front door: npx kestrel.markets prove runs with no key and no config at all.)

Recompute the proof locally, byte for byte

A proof URL is not asking to be believed. certify fetches the proof's evidence bundle, re-projects the Blotter on your machine with the shipped projector, and asserts the bytes match the hosted result:

npx kestrel.markets certify https://kestrel.markets/proof/art_f576347572a410a52647cf90
REPRODUCED  reproduced=true  published_blotter=sha256:…  local_blotter=sha256:…

When the published and local hashes are equal, you have not trusted the server's numbers — you have regenerated them.

Verify a stranger's proof

certify reproduces the computation; verify checks the signature. Point it at any proof URL — one you did not run, from an account you do not have — and it re-verifies the Grade's Ed25519 signature against the platform's independently fetched published keys:

npx kestrel.markets verify https://kestrel.markets/proof/art_f576347572a410a52647cf90
VERIFIED  proof=art_f576347572a410a52647cf90  kid=ksign-2026-07-prod  epoch=1

Public keys can check a signature, never create one, so this proves the platform signed exactly this record — and you learned it without trusting the page that served it.

The workflow the four verbs carry

Threaded together, that is the loop: run → prove → recompute → verify a stranger's. Someone runs a session and shares a proof URL; anyone who holds it recomputes the record (certify) and re-checks the signature (verify) on their own machine.

These four verbs reach the hosted funnel to mint and check proof URLs, and the local runtime replays the committed regime tapes offline. For the reference verb-by-verb surface, read the CLI.

See it in kestrel

You have already seen it: the three commands above are the workflow. Keep the capability one command away — drop the kestrel.markets MCP server into your client so the next session opens where this one left off, no account in between.

Recompute it

Every claim in this unit recomputes from a certified proof — no account, no card.

/proof/art_f576347572a410a52647cf90
Keep readingThe one authorization primitive