Command Line Tools

in-toto provides various command line tools that you can use to generate, consume, modify and verify in-toto metadata. Detailed usage instructions for each tool, along with examples, are provided below.


Cryptographic Signatures

in-toto metadata is signed with cryptographic keys. The CLI accepts key files in standard PEM format. See in-toto#662 for details about key generation.

Evidence Generation

Supply Chain Verification
