Blobs and principals
Store and announce immutable file content:
bnw blob put ./document.pdf --media-type application/pdfbnw blob inspect <BLOB_ID>bnw blob get <BLOB_ID>bnw blob get <BLOB_ID> ./document-copy.pdfWhen the output path is omitted, blob get uses the original filename from the signed blob metadata. If no safe filename is available, it falls back to the blob ID. Existing files are never overwritten.
Encrypt a file for one or more principals before it enters the replicated object store:
bnw blob put-private ./contract.pdf \ --recipient <RECIPIENT_BNW_ID> \ --media-type application/pdf
bnw blob get-private <MANIFEST_CONTENT_ID>bnw blob get-private <MANIFEST_CONTENT_ID> ./contract-copy.pdfbnw blob inboxbnw blob inbox --unreadput-private prints three identifiers. The signed manifest is announced to every recipient’s inbox, so recipients can discover it with blob inbox without being sent its ID out of band. The plaintext ID is only a local integrity reference, while the ciphertext blob ID identifies the encrypted bytes transferred between nodes. Filename, MIME type, plaintext hash, content key, nonce, and encryption format are sealed separately for every recipient. New files are streamed through independently authenticated 256 KiB plaintext chunks and never buffered in full. The sender is automatically included as a recipient. Successful get-private retrieval marks the local inbox entry opened.
Publish the local key as a typed principal:
bnw principal publish human --name "Oliver"bnw principal publish agent --name "Research Agent"bnw principal listbnw principal inspect <BNW_ID>Grant a different principal narrowly scoped authority and later revoke it:
bnw delegate grant <SUBJECT_BNW_ID> \ --capability research:request \ --capability channel:post \ --expires-at 1893456000
bnw delegate revoke <DELEGATION_CONTENT_ID> --reason "access removed"Capability strings are application-neutral. BNW verifies who delegated what, to whom, and for what time window; local policy can then allow, deny, or require human approval.
