CLI

The CLI bundles the kernel and contracts (they stay private and unpublished so phase 6 can change them freely).

iro dev [--headless]      # link a project into Iro, hot reload from Vite
iro build [--project .]   # checked contracts + UI bundle + service file
iro types                 # generate .iro/contracts.d.ts for AppContracts merging
iro validate              # manifest + contracts + build output checks
iro keygen                # Ed25519 publisher key (passphrase-encrypted file)
iro pack [--sign]         # .iropkg package, optionally signed
iro catalog init|add|verify|revoke  # static signed catalog JSON
  • iro dev serves one app over the developer socket (Developer mode only, run/dev.sock, 0600). Later links that ask for nothing new apply directly; anything new shows the sheet again as an update.
  • iro build inlines the SDK into one ESM service file per entry (esbuild, pinned), keeping service bundles dependency-free.
  • iro keygen and iro pack --sign ask for the publisher key file’s passphrase without echoing it. Scripted releases read IRO_KEY_PASSPHRASE; iro keygen --encrypt converts an older unencrypted file. Keep the encrypted file and its passphrase in your password manager.