PostQuantum.DataProtection.Cli 1.0.0

There is a newer version of this package available.
See the version list below for details.
dotnet tool install --global PostQuantum.DataProtection.Cli --version 1.0.0
                    
This package contains a .NET tool you can call from the shell/command line.
dotnet new tool-manifest
                    
if you are setting up this repo
dotnet tool install --local PostQuantum.DataProtection.Cli --version 1.0.0
                    
This package contains a .NET tool you can call from the shell/command line.
#tool dotnet:?package=PostQuantum.DataProtection.Cli&version=1.0.0
                    
nuke :add-package PostQuantum.DataProtection.Cli --version 1.0.0
                    

pq-dp — diagnostics CLI for PostQuantum.DataProtection

License: MIT

A tiny dotnet tool that inspects PostQuantum.DataProtection envelope XML files on disk.

⚠️ Preview (0.1.0-preview.4). Tracks the core preview cadence.

Install

dotnet tool install --global PostQuantum.DataProtection.Cli --prerelease

Use

pq-dp inspect keys/data-protection/key-c6b3b03f-b73a-477b-92e5-d19ae0e0b5fd.xml

Sample output:

File:                keys/data-protection/key-c6b3b03f-b73a-477b-92e5-d19ae0e0b5fd.xml
Format version:      1
Mode:                Hybrid
KEM algorithm:       ML-KEM-768
Public key id:       pq-mlkem768-4411e03446f5
KEM ciphertext:      1088 bytes
Classical wrap:      236 chars
AES-GCM nonce:       12 bytes
AES-GCM tag:         16 bytes
AES-GCM ciphertext:  120 bytes

No secrets are printed. The CLI reads only the envelope's routing metadata.

What it can't do (yet)

  • Decrypt anything. The CLI has no host KEK, no ML-KEM secret key, no access to the keystore. Decryption stays inside the host process for a reason — see docs/threat-model.md.
  • Generate or rotate keys. Use the runtime API (PostQuantumKeyManager.RotateAsync) or an admin endpoint in your host.

Uninstall

dotnet tool uninstall --global PostQuantum.DataProtection.Cli

To God be the glory — 1 Corinthians 10:31.

Product Compatible and additional computed target framework versions.
.NET net10.0 is compatible.  net10.0-android was computed.  net10.0-browser was computed.  net10.0-ios was computed.  net10.0-maccatalyst was computed.  net10.0-macos was computed.  net10.0-tvos was computed.  net10.0-windows was computed. 
Compatible target framework(s)
Included target framework(s) (in package)
Learn more about Target Frameworks and .NET Standard.

This package has no dependencies.

Version Downloads Last Updated
1.0.2 171 8/20/2026
1.0.1 126 6/30/2026
1.0.0 135 6/30/2026
0.1.0-preview.7 84 6/4/2026
0.1.0-preview.6 83 6/4/2026
0.1.0-preview.5 90 6/4/2026
0.1.0-preview.4 88 6/4/2026

0.1.0-preview.4: First public preview. Diagnostics CLI for PostQuantum.DataProtection. Currently supports: pq-dp inspect <path-to-key.xml>.