smallstep/cli
🧰 A zero trust swiss army knife for working with X509, OAuth, JWT, OATH OTP, etc. observed · 2026-08-28
Health v2 · maintenance only
95/100
- Activity 99
- Release rhythm 87
- Longevity 100
How is this computed?
round(0.45*activity + 0.35*rhythm + 0.20*longevity); archived -> min(score, 10) — computed 2026-09-03. Adoption (stars, forks) is never an input.
- gap_med: 12.0
- age_days: 2969
- days_rel: 84
- days_push: 7
- n_releases_24m: 17
Adoption not part of the score
4317 stars · 315 forks observed · 2026-08-28
What it is AI-extracted, prompt v1, taxonomy v1, 2026-08-29, confidence not recorded
Step CLI is a Go-based command-line tool for building, operating, and automating PKI systems, working with X.509 certificates, JWTs, OAuth tokens, SSH certificates, and TOTP. It also serves as the client for the step-ca online Certificate Authority.
Use cases
- create and sign self-signed or CA-signed TLS certificates
- inspect and lint X.509 certificates on disk or from a remote server
- generate and validate JWTs and JWKs
- obtain and manage OAuth access tokens
- install root certificates into the system trust store
- generate and verify TOTP tokens for MFA
- issue certificates from a private ACME certificate authority
- create certificate signing requests and key pairs
When to choose
- you need a general-purpose crypto and PKI toolkit from the command line
- you run or connect to step-ca or Smallstep Certificate Manager
- you want to automate certificate issuance and renewal in scripts or CI/CD
- you need to inspect, lint, or bundle certificates quickly
- you want safe defaults for common crypto operations without being a security engineer
When to avoid
- you need a GUI or web-based certificate management interface
- you only need a full CA server - use step-ca instead
- you need library bindings to embed in an application rather than a CLI
- you need Windows-native tooling beyond the provided binaries
Facets
cli-tool · maturity active
cryptography security cli developer-tools security developer-tools windows cli cross-platform pki x509 tls certificates jwt oauth ssh-certificates totp mfa zero-trust acme step-ca-client jose command-line devops linux macos
10 sources
- readme: https://github.com/smallstep/cli · fetched 2026-08-28 · ec3ba3338c0b
- homepage: https://smallstep.com/cli · fetched 2026-08-29 · 9c48775c39c1
- site_page: https://smallstep.com/docs/step-ca/renewal · fetched 2026-08-29 · 2bea675351c4
- site_page: https://smallstep.com/docs/tutorials · fetched 2026-08-29 · a66c2566f290
- site_page: https://smallstep.com/docs/step-ca · fetched 2026-08-29 · 5a9f5cd95a7d
- site_page: https://smallstep.com/docs/step-ca/provisioners · fetched 2026-08-29 · 516b658a255b
- site_page: https://smallstep.com/docs/step-cli · fetched 2026-08-29 · 75c7923021dd
- site_page: https://smallstep.com/docs/step-cli/installation · fetched 2026-08-29 · 6b614e5007e1
- site_page: https://smallstep.com/docs/step-cli/reference/certificate/inspect · fetched 2026-08-29 · e889f9259cf3
- site_page: https://smallstep.com/webforms/pricing · fetched 2026-08-29 · 2b58cb459100
Member repositories
| Repository | Role | Health v2 |
|---|---|---|
| smallstep/cli | main | 95 |
For agents
Data as of 2026-08-30T08:39:29.467469+00:00 · Report a problem