Skip to main content

CLI Sub Accounts

Use the subaccounts command group (alias: sa) to operate merchant sub-accounts.

Commands

Create

List

Balance

TTL Policy (Merchant)

Token and grant TTL inputs are validated against these effective policy values.

Mint Delegation Token

Mint Child Delegation Token

Freeze

Unfreeze

Previously revoked delegation tokens are not reactivated; mint new token(s) after unfreeze if required.

Drain

Withdraw

--signing-grant and --passkey-file are mutually exclusive. --passkey-file remains available as an interactive fallback.

Withdraw to Bank (One-Shot)

This command mirrors split proxy-email OTP automation. No manual OTP prompt is required. --automation-token and --delegation-token are mutually exclusive. --signing-grant and --passkey-file are mutually exclusive. For API-key initiated withdraw-bank calls, pass one policy token (--automation-token or --delegation-token) and one signing authorization (--signing-grant). --bank-id accepts a bank identifier value (PAJ bank id, bank code, or bank name).

Mint Automation Token

Revoke Automation Token

Mint Signing Grant

This command starts a browser intent, opens the approval URL, and polls until passkey approval completes. Legacy fallback (manual payload) remains available:
Use --no-open if your environment cannot auto-open a browser. --ttl must be within merchant TTL policy bounds.

Revoke Signing Grant

Create Policy

Dry Run Policy

Create Trigger Subscription

List Trigger Subscriptions

Create Execution Intent

Approve Execution Intent

Reject example:

Release Execution Intent By Signal

Create Balance Rule

Close

Passkey Signature File

Interactive fallback operations can use --passkey-file JSON with this shape: