Command-line reference
Release 1.0.31. Every block on this page is what the program printed for --help (or the named command), captured from the 1.0.31 Linux build. The download carries eight programs; din is the one you type, and it runs the field, the console, the importer and the dependency audit for you.
din
din - your own field, on your own box. Nothing leaves your machine.
USAGE
din status: is the field up, what is in it, next steps
din setup --isolated a NEW field of your own in a tree of your own:
own token, own store, own auto-picked loopback
port, started without root, Postgres or systemd.
--port auto|N --prefix DIR --dry-run --force
din field start start the field on loopback and wait for it
din field stop stop the field this install started; it stays
stopped (nothing starts it on its own) until
`din field start`
din field status ask the field how it is
din field ensure start it if it is down and was not stopped on
purpose (what every verb below does first)
din autostart on|off|status also start it at login: a systemd user unit or
XDG entry, a LaunchAgent, or a hidden logon task.
Per user, no admin. `off` removes what `on` made.
`on --with-push` also runs `din hosted push`
at login (a hosted console must be connected).
din field log [-n N] the last N lines of the field's log
din field binding which field is ACTIVE, which are archived and KEPT
din field activate <id> bring an archived field back, whole (one at a time)
din agent list which agents are wired here, and which one your
field serves (ACTIVE) or has set aside (ARCHIVED)
din agent add <name> [--yes] wire claude-code, cursor or opencode with the
plugin's own installer. On free it says first what
a second agent does and asks at a terminal.
din agent remove <name> unwire it; its records stay in your field, kept
din console [--no-open] run the LOCAL console on loopback
din import [args...] the Upstream on-ramp (din import --dry-run first)
din recall <question> the compact, trust-marked digest
din query <filter> rows as TSV: facet=claims&state=disputed
din brief <question> the graded brief: decided / unproven / contradicted
din dep-audit [args] dependency risk: what your code REALLY imports,
crossed with whether the upgrade was ever shown.
JSON by default; --tsv for the human table.
READ-ONLY - it never writes the store.
din plugin install [args] install the Claude Code plugin from this bundle
(also installed as `din-recall`, which the
plugin's /din recall calls by that name)
din activate <KEY> check a paid license key in (needs curl) and
install the signed entitlement it earns; it is
verified here first, or nothing is written.
`din activate -` reads the key from stdin.
din activate --file <PATH> the same OFFLINE, from a saved check-in reply
din activate --renew carry a paid install into its new billing period
from the saved key; silent when it works.
`din autostart on` runs it for you.
din license what tier this install runs as, and who decides
din where every path and setting, resolved
din hosted connect|push|status|recall
ONLY if you have a HOSTED DIN console: push this
install's records to it (the one command that
sends records off this machine, and only when
run). `din hosted help` for the details.
din version
OPTIONS
--project P --since D --until D scope recall, query and brief to one project
or a date window (dates are YYYY-MM-DD)
--k N recall: how many hits (1..50)
--json machine-readable, same rows, same grades.
On `din status` it is one JSON object with
the programs, the field, the token and the
plugin - the headless way to check an
install. Exit 0 = usable, 1 = incomplete.
--timeout-ms N give up on the field after N ms (default 8000)
START ON USE
status, console, recall, query, brief, field binding|activate and
import --status start the field first when it is down, the same way
`din field start` does, and say so on stderr. Not after `din field stop`,
never on a port something else holds, and not with DIN_FIELD_AUTOSTART=off.
WHERE IT LOOKS
$DIN_PREFIX, else the prefix this binary was installed into, else ~/din.
Settings come from <prefix>/.din/field.env; the process environment wins over
it. `din where` prints what was resolved and from where.
($DIN_HOME is NOT this. That one is the plugin's own state directory.)
din activate
USAGE
din activate <LICENSE_KEY> check the key in with the issuer and install the
signed entitlement it answers with (needs curl)
din activate - the same, the key read from stdin (keeps it out
of your shell history)
din activate the same, with the key saved in license.key
din activate --file <PATH> OFFLINE: install a saved check-in reply (the JSON
POST /api/license/verify answered) or a bare
signed envelope. No network, no curl.
din activate --renew check the saved key in again: carries a paid
install into its new billing period. Prints
nothing when it works, one line when it does
not. `din autostart on` runs it once a day.
--url <BASE> the issuer, default https://api.dinctrl.com
(DIN_BILLING_URL sets it too)
Nothing is written unless the signed entitlement verifies on this box.
din setup --isolated
din setup --isolated - your own field, in your own tree, with no admin.
USAGE
din setup --isolated [--port auto|N] [--prefix DIR] [--force] [--dry-run]
WHAT IT LAYS DOWN, under the prefix (default: this install's prefix, else ~/din)
.din/field.token a freshly minted token, 0600, never printed
.din/field.env the settings, so `din recall` in this tree asks THIS field
.din/field.pid the running daemon, written after the kernel is asked
records/ an empty store. This field serves these and nothing else.
logs/field.log
field.sh start | stop | restart | status | log
README-FIELD.md how to run it, in the tree, so it travels with the tree
OPTIONS
--isolated required. The one recipe this command has.
--port auto|N auto (the default) scans for a free loopback port.
A number is used as given, and refused if it is taken.
--console-port N the same, for `din console` in this tree.
--prefix DIR where the tree goes.
--programs DIR where the programs are, when this tree borrows them from
an install elsewhere. Default: this install's bin/.
--force re-mint the token over an EXISTING field at this prefix.
Records are never deleted; the old token is kept beside
the new one as field.token.previous.
--no-start lay it down, do not start the daemon.
--dry-run print every step, touch nothing.
NO ROOT. NO POSTGRES. NO SYSTEMD. One loopback port, one token, one daemon
started by the user who will use it. It does not touch any other field.
NOT THE PROVISIONER. `provision-instance.sh` stands up a whole INSTANCE: a
database, a service manager, a machine. This makes a workspace its own private
field on a box that already works. If you are reaching for the provisioner to
get a tree of your own, this is the command you wanted.
din import (din-import)
din import [args...] runs din-import with the same arguments.
din-import - point DIN at your chats and it works.
Bare `din-import` runs the wizard. It looks before it asks, it tells you what an
import will cost before it starts, and it runs the review on your own inference:
your own API key by default, or your own local Claude if you pick that instead.
DIN never runs model calls on our account.
USAGE
din-import wizard (default entry point)
din-import --source claude-code [--path P] detected sessions on disk
din-import --source codex [--path P] Codex rollouts on disk
din-import --source gemini-cli [--path P] Gemini CLI sessions on disk
din-import --source chatgpt --export P the data-export zip or directory
din-import --source grok --export P Grok chats in an X (Twitter) archive
din-import --source cline [--path P] Cline, Kilo Code or Roo Code tasks
din-import --source qwen [--path P] Qwen Code sessions on disk
din-import --source claude-mem [--path P] a claude-mem store's JSONL spine
din-import --source upload --file P generic, against the record contract
din-import --source inbox whatever you dropped in ~/din/inbox
din-import --dry-run the plan and a sample record, no calls
din-import --apply run it for real, on your own inference
din-import --model <id> pick the review model
din-import --max-spend <amount> pause and ask at this running estimate
din-import --status progress, running cost, state
din-import --pause | --resume | --stop process control
din-import --log the verbose log for bug reports
din-import --advanced print the plan, run nothing
din-import --workers <n> override concurrency
din-import --tools show the tooling this wrapper drives
WHERE YOUR CHATS GO
~/din/inbox. Drop exported conversations there and run din-import: the inbox
is scanned on every run, offered like any other source, and each file in it is
either read or named with the reason it cannot be. The directory and a short
guide (README.txt) are created the first time this runs. $DIN_HOME/inbox if
that is set, $DIN_INBOX if you set that.
OTHER FLAGS
--limit <n> consider at most this many conversations
--home <dir> state directory (default $DIN_HOME or ~/.din/import)
--field <dir> the record store this import writes into
--prompt <file> the interpretive contract to use instead of the one this
build ships. Bring your own: it is sent verbatim, exactly
as the shipped one is. Also settable as DIN_PROMPT
--run <id> operate on this run id instead of the latest
--yes answer yes to every confirmation (scripting)
--retry-escalated with --resume: try again a run that stopped retrying
after your provider refused it repeatedly
--stagger <secs> seconds between worker starts (default 15)
-h, --help this
-V, --version version
DRY RUN IS THE DEFAULT WHEN NOBODY IS THERE TO ASK
Run without a terminal and without --apply and you get the dry run: the plan,
the estimate, and a sample of the record this import would build, with no
model call and nothing written to your field. --apply is how you say go.
Interactive runs still ask on the cost screen instead.
WHAT IT COSTS
Nothing to us. The review runs on your own key or your own account and the
bill goes to your provider. --dry-run prints the estimate and imports nothing.
din dep-audit (din-dep-audit)
din dep-audit [args] runs din-dep-audit, passing its flags through. From din the report is JSON by default; --tsv asks for the table.
usage: din-dep-audit [-h] [--store STORE] [--json] [--top TOP]
[--origin {external,stdlib,internal,unknown,all}]
[--lang LANG] [--dep DEP] [--stale-days STALE_DAYS]
[--evidence] [--out OUT] [--fail-over FAIL_OVER]
[--now NOW]
Dependency risk from the call graph crossed with the honest record. READ-ONLY:
it never writes the store and never touches code.
options:
-h, --help show this help message and exit
--store STORE the durable record store dir (else $STORE). No baked-in
default.
--json the full report as JSON (schema din-dep-audit/1)
--top TOP rows to print (default 20; 0 = all)
--origin ORIGIN which origins to report (default external; repeatable)
--lang LANG restrict to a language (repeatable)
--dep DEP restrict to a named dependency (repeatable)
--stale-days DAYS no activity in the record for this long = quietly
unmaintained (default 120)
--evidence in TSV mode, print the cited claims/experiments under
the table
--out OUT write the report here instead of stdout - the ONLY path
this tool writes
--fail-over RISK exit 3 if any reported dependency scores above this risk
(a CI gate)
--now NOW fix 'now' for reproducible output (tests)
din-record
The record producer. The plugin uses it to turn a session into records.
usage: din-record --run RUN [--model MODEL] [--no-model] [--repo-root REPO_ROOT]
[--prompt PROMPT] [--timeout TIMEOUT] [--org-node ORG_NODE]
[--by BY] [--by-kind {person,org,unknown}] [--project PROJECT]
DIN CTRL receipted record producer (Rust port of receipt/record.py)
options:
--run RUN run dir, e.g. runs/46
--model MODEL model for the ONE interpretive call
--no-model observed facets only (honest-failure path, no model call)
--repo-root PATH where the FROZEN contracts live (default: two levels up)
--prompt PATH the interpretive contract to use, overriding --repo-root.
Without it: DIN_PROMPT, then <repo-root>/PROMPT-...-v1.md,
then the sealed din-contract provider.
--timeout TIMEOUT
--org-node ORG_NODE org node id for the run's channel (e.g. echoron)
--by BY identity.by id - who this run is attributed to
--by-kind KIND kind for --by (default person)
--project PROJECT project_affiliation.primary for this run. Without it:
the base name of --repo-root when one is given, else
the run's own label (DIN_CHANNEL, else the base name
of the session cwd in <run>/meta.json), else empty.
dinctrl-store
The one writer that places records in the store.
dinctrl-store - DIN CTRL durable record store
USAGE:
dinctrl-store ingest --runs <root> --store <dir> [--b6-patterns FILE]
dinctrl-store check-ids --store <dir>
dinctrl-store backfill-transcripts --store <dir> [--runs <root>] [--write]
[--b6-patterns FILE] [--b6-strict]
dinctrl-store backfill-transcripts --refilter --store <dir> [--write]
[--b6-patterns FILE] [--b6-strict]
OPTIONS:
--runs <root> runs/ root to scan: <root>/*/record.json and
<root>/*/records/*.json
--store <dir> durable store dir; records land in <dir>/<channel>/<id>.json
--write backfill-transcripts only: write, instead of listing
--refilter backfill-transcripts only: re-derive EXISTING sidecars
through the personal-content filter and the table
--b6-patterns FILE
personal-content policy (default $DIN_B6_PATTERNS, else
b6-patterns.json beside this binary or in ../scripts/,
else the built-in copy), as din-session-record finds it
--b6-strict backfill-transcripts only: redact the ambiguous shelf too
-h, --help show this message
ingest writes <dir>/<channel>/<id>.transcript.txt beside each new conversation
record whose run has a session.jsonl: the session's text, credentials
redacted, capped at DIN_TRANSCRIPT_MAX_BYTES (default 2 MiB). The field
searches it, so a record made without a model is found by what was said.
Personal content goes first: the producer's B6 filter runs over the text, set
from the record's provenance.b6 (always on when the record was filtered;
otherwise on unless DIN_B6=0). When B6 cannot run, NO sidecar is written for
that record and it is counted; the unfiltered text is never written.
backfill-transcripts is READ-ONLY unless --write. It lists every conversation
record with no sidecar whose run (identity.path, else <runs>/<channel>) still
holds the exact session.jsonl the record was made from, and with --write
writes those sidecars, filtered as ingest filters them. Exit 1 when read-only
and some are missing, or when B6 could not run for some.
backfill-transcripts --refilter is READ-ONLY unless --write. It runs every
existing <dir>/<channel>/<id>.transcript.txt (and <dir>/<id>.transcript.txt)
through B6 and the table, using the record beside it when there is one, and
lists (with --write rewrites) only those whose bytes change. It needs no run,
so <dir> may be a quarantine copy. It never touches a record or the manifest.
Exit 1 when any would change or B6 could not run for any; with --write, 1
when B6 could not run for any or a write failed.
check-ids is READ-ONLY. It lists every stored code record whose file is named
by the old content-hash-only id, which a re-ingest by this build would store a
second time under its new id. Exit 0 when there are none, 1 when there are.
ingest itself never stores such a record twice: a code record whose file is
absent under its new id, but present under its legacy id with the same card
and content hash (check-ids' own test), is left alone, printed as `~`, and
counted as `legacy present` in the summary. No file is renamed, rewritten or
deleted and no manifest line is added for it.
PHASE 1: no sqlite index and no git staging are performed.
din-contract
din-contract - the sealed interpretive contract provider
din-contract write the contract to stdout
din-contract --check open the blob and report on it, WITHOUT printing it
din-contract --sha256 the sha256 of the contract, and nothing else
din-contract --help
din-contract --version
The contract is compiled into this binary as an encrypted blob. It is written
to stdout so a caller can capture it; it is never written to a file here and
never reaches the customer's disk through this program.
Refuses to write to a terminal unless you pass --to-terminal, so that a stray
invocation in a shared shell, a screen share or a CI log does not print the
contract into a scrollback buffer nobody meant to fill.
streamfieldd and dind-console
The field server and the local console. They print no help: each needs its token in the environment, and din field start and din console start them with it. Run without one, each says what it needs:
streamfield: FIELD_TOKEN is required (env only, never hardcoded)
dind-console: DASH_FIELD_TOKEN is required - it is this tenant's own field token.
usage: DASH_FIELD_TOKEN=<token> ./dind-console (run.sh reads it from a 0600 file)
Versions
Every program answers --version:
din 1.0.31
din-contract 1.0.31
din-dep-audit 1.0.31
din-import 1.0.31
din-record 1.0.31
dinctrl-store 1.0.31
dind-console 1.0.31
streamfieldd 1.0.31