CLI
The CLI bundles the kernel and contracts (they stay private and unpublished so phase 6 can change them freely).
iro dev [--headless] # link a project into Iro, hot reload from Vite
iro build [--project .] # checked contracts + UI bundle + service file
iro types # generate .iro/contracts.d.ts for AppContracts merging
iro validate # manifest + contracts + build output checks
iro keygen # Ed25519 publisher key (passphrase-encrypted file)
iro pack [--sign] # .iropkg package, optionally signed
iro catalog init|add|verify|revoke # static signed catalog JSON
iro devserves one app over the developer socket (Developer mode only,run/dev.sock, 0600). Later links that ask for nothing new apply directly; anything new shows the sheet again as an update.iro buildinlines the SDK into one ESM service file per entry (esbuild, pinned), keeping service bundles dependency-free.iro keygenandiro pack --signask for the publisher key file’s passphrase without echoing it. Scripted releases readIRO_KEY_PASSPHRASE;iro keygen --encryptconverts an older unencrypted file. Keep the encrypted file and its passphrase in your password manager.