Key, workflow-state, and update
bro command reference for key, workflow-state, and update.
See Init and config for shared conventions and environment variables.
bro key
Virtual-key management
Usage: bro key <COMMAND>
bro key sign
Mint a new brvk_ virtual key for a user. v1 does not sign a JWT — it creates a DB-backed virtual key and prints the plaintext once
Usage: bro key sign [OPTIONS] --user <USER>
| Flag | Description |
|---|---|
-u, --user <USER> | The owning user id |
-d, --db <DB> | Database URL — any backend sea-orm supports (sqlite://…, postgres://…, mysql://…) [default: sqlite://./bitrouter.db] |
--policy <POLICY> | Optional policy id to bind to the key (the policy_id column) |
Mints a virtual key bound to an access-control policy — the per-key guardrails surface (allowed models, budgets, rate limits), distinct from routing policies. See access-control policies.
bro key sign --user ci --policy nightly-capbro workflow-state
Workflow-state trace/replay utilities
Usage: bro workflow-state <COMMAND>
Internal benchmark tooling — the plumbing behind the published Terminal-Bench reports (trace capture, outcome bundling, reward feedback), not a production user surface. It's documented here only for completeness; you almost certainly don't need it.
bro workflow-state classifier-bakeoff
Evaluate a shadow task/role/progress/risk classifier without routing
Usage: bro workflow-state classifier-bakeoff [OPTIONS] --fixtures <FIXTURES> --output <OUTPUT>
| Flag | Description |
|---|---|
--fixtures <FIXTURES> | Directory tree containing frozen workflow-state fixture JSON files |
--submission <SUBMISSION> | Optional candidate submission JSON. Omit to evaluate the compiled deterministic scorecard as an uncalibrated baseline |
--output <OUTPUT> | Output path for the deterministic manifest and evaluation report |
bro workflow-state bundle
Build a deterministic benchmark trace bundle
Usage: bro workflow-state bundle [OPTIONS] --run-label <RUN_LABEL> --traces <TRACES> --cloud-usage <CLOUD_USAGE> --output-dir <OUTPUT_DIR>
| Flag | Description |
|---|---|
--run-label <RUN_LABEL> | Run label stored in run-artifact.json |
--traces <TRACES> | Daemon workflow trace JSONL |
--cloud-usage <CLOUD_USAGE> | BitRouter Cloud usage snapshot JSONL |
--outcomes <OUTCOMES> | Optional request-scoped benchmark outcome JSONL. Omit when task or episode outcomes will be submitted through the Eval Exchange |
--policy-decisions <POLICY_DECISIONS> | Optional policy routing decision JSONL from BITROUTER_POLICY_DECISION_JSONL |
--output-dir <OUTPUT_DIR> | Output directory for traces/cloud usage/outcomes/artifacts |
bro workflow-state metering-usage
Export daemon metering rows as usage JSONL for benchmark bundles
Usage: bro workflow-state metering-usage [OPTIONS] --database-url <DATABASE_URL> --output <OUTPUT>
| Flag | Description |
|---|---|
--database-url <DATABASE_URL> | Database URL for the daemon metering DB, for example sqlite:///path/bitrouter.db |
--output <OUTPUT> | Output usage JSONL path |
--impute-price <IMPUTE_PRICES> | Impute charges as provider:model=uncached,cache_read,cache_write,output. Legacy input,output is accepted only for records with no cache usage |
--since <SINCE> | Inclusive RFC3339 lower bound. Defaults to the current UTC month |
--until <UNTIL> | Exclusive RFC3339 upper bound. Only used with --since; defaults to now |
bro workflow-state reliability-report
Replay persisted provider reliability state into a deterministic JSON report
Usage: bro workflow-state reliability-report --database-url <DATABASE_URL> --config <CONFIG> --output <OUTPUT>
| Flag | Description |
|---|---|
--database-url <DATABASE_URL> | Database URL for the daemon policy DB |
--config <CONFIG> | Frozen BitRouter config that defines the reliability thresholds |
--output <OUTPUT> | Output JSON report path |
bro workflow-state policy-oracle
Estimate policy cost coverage and savings without changing live routing
Usage: bro workflow-state policy-oracle --traces <TRACES> --cloud-usage <CLOUD_USAGE> --policy-lock <POLICY_LOCK> --policy <POLICY> --effective-cost-factor <EFFECTIVE_COST_FACTOR_PPM> --target-savings <TARGET_SAVINGS_PPM> --output <OUTPUT>
| Flag | Description |
|---|---|
--traces <TRACES> | Protocol-native daemon workflow trace JSONL from the baseline run |
--cloud-usage <CLOUD_USAGE> | Request-settled usage JSONL for the same baseline run |
--policy-lock <POLICY_LOCK> | Policy lock containing the candidate routes to replay |
--policy <POLICY> | Named policy within the lock |
--effective-cost-factor <EFFECTIVE_COST_FACTOR_PPM> | Candidate effective cost divided by baseline cost, including any expected token, retry, or turn inflation (for example 0.24) |
--target-savings <TARGET_SAVINGS_PPM> | Desired end-to-end savings fraction. Repeat for multiple targets |
--output <OUTPUT> | Output JSON report path |
bro workflow-state reconcile-metering
Reconcile selected metering rows against request-scoped receipts
Usage: bro workflow-state reconcile-metering [OPTIONS] --database-url <DATABASE_URL> --request-id <REQUEST_IDS>
| Flag | Description |
|---|---|
--database-url <DATABASE_URL> | Database URL for the daemon metering DB |
--api-base <API_BASE> | Inference API root ending in /v1 [default: https://api.bitrouter.ai/v1] |
--api-key-env <API_KEY_ENV> | Environment variable containing the inference key [default: BITROUTER_API_KEY] |
--credentials-file <CREDENTIALS_FILE> | Protected BitRouter Cloud credential file containing a static API key. OAuth credentials are never refreshed for settlement |
--request-id <REQUEST_IDS> | Exact request id to reconcile. Repeat for every selected row |
--price <PRICES> | Frozen price as provider:model=uncached,cache_read,cache_write,output. Repeat a provider/model pair for alternative schedules; settlement accepts only one distinct candidate that reconstructs the receipt |
--max-attempts <MAX_ATTEMPTS> | Maximum durable receipt fetches per request [default: 12] |
--poll-interval-ms <POLL_INTERVAL_MS> | Delay between pending-receipt polls [default: 1000] |
bro workflow-state apply-reward-feedback
Apply task rewards to cheap replacement transitions before the next round
Usage: bro workflow-state apply-reward-feedback --database-url <DATABASE_URL> --traces <TRACES> --cloud-usage <CLOUD_USAGE> --outcomes <OUTCOMES> --policy-decisions <POLICY_DECISIONS>
| Flag | Description |
|---|---|
--database-url <DATABASE_URL> | Database URL for the policy daemon DB, for example sqlite:///path/bitrouter.db |
--traces <TRACES> | Daemon workflow trace JSONL for the just-finished benchmark group |
--cloud-usage <CLOUD_USAGE> | Exact, reconciled usage JSONL for the same benchmark group |
--outcomes <OUTCOMES> | Benchmark outcome JSONL for the just-finished benchmark group |
--policy-decisions <POLICY_DECISIONS> | Policy routing decision JSONL from BITROUTER_POLICY_DECISION_JSONL |
bro update
Update the installed bitrouter binary in place to the latest release. Follows prereleases by default while pre-1.0. For Homebrew / cargo install installs it prints the right upgrade command instead
Usage: bro update [OPTIONS]
| Flag | Description |
|---|---|
--check | Report whether a newer version exists, then exit without changing anything |
--tag <TAG> | Update (or downgrade) to a specific release tag, e.g. 1.0.0-alpha.18. Named --tag to avoid clashing with the global --version flag |
--stable | Only consider stable (non-prerelease) releases |
--restart | After a successful update, restart a running daemon so it serves the new binary |
-y, --yes | Skip the confirmation prompt |
bro updateUpdates the installed binary in place to the latest release — follows prereleases by default while pre-1.0. Homebrew and cargo install builds update through their own package manager instead.
How is this guide?