Key, workflow-state, and update

bro command reference for key, workflow-state, and update.

6 min readEdit this page

See Init and config for shared conventions and environment variables.

bro key

Virtual-key management

Usage: bro key <COMMAND>

bro key sign

Mint a new brvk_ virtual key for a user. v1 does not sign a JWT — it creates a DB-backed virtual key and prints the plaintext once

Usage: bro key sign [OPTIONS] --user <USER>

FlagDescription
-u, --user <USER>The owning user id
-d, --db <DB>Database URL — any backend sea-orm supports (sqlite://…, postgres://…, mysql://…) [default: sqlite://./bitrouter.db]
--policy <POLICY>Optional policy id to bind to the key (the policy_id column)

Mints a virtual key bound to an access-control policy — the per-key guardrails surface (allowed models, budgets, rate limits), distinct from routing policies. See access-control policies.

bro key sign --user ci --policy nightly-cap

bro workflow-state

Workflow-state trace/replay utilities

Usage: bro workflow-state <COMMAND>

Internal benchmark tooling — the plumbing behind the published Terminal-Bench reports (trace capture, outcome bundling, reward feedback), not a production user surface. It's documented here only for completeness; you almost certainly don't need it.

bro workflow-state classifier-bakeoff

Evaluate a shadow task/role/progress/risk classifier without routing

Usage: bro workflow-state classifier-bakeoff [OPTIONS] --fixtures <FIXTURES> --output <OUTPUT>

FlagDescription
--fixtures <FIXTURES>Directory tree containing frozen workflow-state fixture JSON files
--submission <SUBMISSION>Optional candidate submission JSON. Omit to evaluate the compiled deterministic scorecard as an uncalibrated baseline
--output <OUTPUT>Output path for the deterministic manifest and evaluation report

bro workflow-state bundle

Build a deterministic benchmark trace bundle

Usage: bro workflow-state bundle [OPTIONS] --run-label <RUN_LABEL> --traces <TRACES> --cloud-usage <CLOUD_USAGE> --output-dir <OUTPUT_DIR>

FlagDescription
--run-label <RUN_LABEL>Run label stored in run-artifact.json
--traces <TRACES>Daemon workflow trace JSONL
--cloud-usage <CLOUD_USAGE>BitRouter Cloud usage snapshot JSONL
--outcomes <OUTCOMES>Optional request-scoped benchmark outcome JSONL. Omit when task or episode outcomes will be submitted through the Eval Exchange
--policy-decisions <POLICY_DECISIONS>Optional policy routing decision JSONL from BITROUTER_POLICY_DECISION_JSONL
--output-dir <OUTPUT_DIR>Output directory for traces/cloud usage/outcomes/artifacts

bro workflow-state metering-usage

Export daemon metering rows as usage JSONL for benchmark bundles

Usage: bro workflow-state metering-usage [OPTIONS] --database-url <DATABASE_URL> --output <OUTPUT>

FlagDescription
--database-url <DATABASE_URL>Database URL for the daemon metering DB, for example sqlite:///path/bitrouter.db
--output <OUTPUT>Output usage JSONL path
--impute-price <IMPUTE_PRICES>Impute charges as provider:model=uncached,cache_read,cache_write,output. Legacy input,output is accepted only for records with no cache usage
--since <SINCE>Inclusive RFC3339 lower bound. Defaults to the current UTC month
--until <UNTIL>Exclusive RFC3339 upper bound. Only used with --since; defaults to now

bro workflow-state reliability-report

Replay persisted provider reliability state into a deterministic JSON report

Usage: bro workflow-state reliability-report --database-url <DATABASE_URL> --config <CONFIG> --output <OUTPUT>

FlagDescription
--database-url <DATABASE_URL>Database URL for the daemon policy DB
--config <CONFIG>Frozen BitRouter config that defines the reliability thresholds
--output <OUTPUT>Output JSON report path

bro workflow-state policy-oracle

Estimate policy cost coverage and savings without changing live routing

Usage: bro workflow-state policy-oracle --traces <TRACES> --cloud-usage <CLOUD_USAGE> --policy-lock <POLICY_LOCK> --policy <POLICY> --effective-cost-factor <EFFECTIVE_COST_FACTOR_PPM> --target-savings <TARGET_SAVINGS_PPM> --output <OUTPUT>

FlagDescription
--traces <TRACES>Protocol-native daemon workflow trace JSONL from the baseline run
--cloud-usage <CLOUD_USAGE>Request-settled usage JSONL for the same baseline run
--policy-lock <POLICY_LOCK>Policy lock containing the candidate routes to replay
--policy <POLICY>Named policy within the lock
--effective-cost-factor <EFFECTIVE_COST_FACTOR_PPM>Candidate effective cost divided by baseline cost, including any expected token, retry, or turn inflation (for example 0.24)
--target-savings <TARGET_SAVINGS_PPM>Desired end-to-end savings fraction. Repeat for multiple targets
--output <OUTPUT>Output JSON report path

bro workflow-state reconcile-metering

Reconcile selected metering rows against request-scoped receipts

Usage: bro workflow-state reconcile-metering [OPTIONS] --database-url <DATABASE_URL> --request-id <REQUEST_IDS>

FlagDescription
--database-url <DATABASE_URL>Database URL for the daemon metering DB
--api-base <API_BASE>Inference API root ending in /v1 [default: https://api.bitrouter.ai/v1]
--api-key-env <API_KEY_ENV>Environment variable containing the inference key [default: BITROUTER_API_KEY]
--credentials-file <CREDENTIALS_FILE>Protected BitRouter Cloud credential file containing a static API key. OAuth credentials are never refreshed for settlement
--request-id <REQUEST_IDS>Exact request id to reconcile. Repeat for every selected row
--price <PRICES>Frozen price as provider:model=uncached,cache_read,cache_write,output. Repeat a provider/model pair for alternative schedules; settlement accepts only one distinct candidate that reconstructs the receipt
--max-attempts <MAX_ATTEMPTS>Maximum durable receipt fetches per request [default: 12]
--poll-interval-ms <POLL_INTERVAL_MS>Delay between pending-receipt polls [default: 1000]

bro workflow-state apply-reward-feedback

Apply task rewards to cheap replacement transitions before the next round

Usage: bro workflow-state apply-reward-feedback --database-url <DATABASE_URL> --traces <TRACES> --cloud-usage <CLOUD_USAGE> --outcomes <OUTCOMES> --policy-decisions <POLICY_DECISIONS>

FlagDescription
--database-url <DATABASE_URL>Database URL for the policy daemon DB, for example sqlite:///path/bitrouter.db
--traces <TRACES>Daemon workflow trace JSONL for the just-finished benchmark group
--cloud-usage <CLOUD_USAGE>Exact, reconciled usage JSONL for the same benchmark group
--outcomes <OUTCOMES>Benchmark outcome JSONL for the just-finished benchmark group
--policy-decisions <POLICY_DECISIONS>Policy routing decision JSONL from BITROUTER_POLICY_DECISION_JSONL

bro update

Update the installed bitrouter binary in place to the latest release. Follows prereleases by default while pre-1.0. For Homebrew / cargo install installs it prints the right upgrade command instead

Usage: bro update [OPTIONS]

FlagDescription
--checkReport whether a newer version exists, then exit without changing anything
--tag <TAG>Update (or downgrade) to a specific release tag, e.g. 1.0.0-alpha.18. Named --tag to avoid clashing with the global --version flag
--stableOnly consider stable (non-prerelease) releases
--restartAfter a successful update, restart a running daemon so it serves the new binary
-y, --yesSkip the confirmation prompt
bro update

Updates the installed binary in place to the latest release — follows prereleases by default while pre-1.0. Homebrew and cargo install builds update through their own package manager instead.

How is this guide?

On this page