Quickstart
This page walks through the first person account, the first machine identity and the first upload in a cell. Your operator gives you the cell’s address and console.
1. Join with a passkey
Section titled “1. Join with a passkey”- Ask your administrator for an invite code. It is valid for 72 hours and shown once.
- Open Server settings in the console and connect to the cell’s address.
- Enter the invite code and press Create passkey and join. Your device creates a passkey; there is no password.
2. Request a machine identity
Section titled “2. Request a machine identity”Your uploading system connects with a machine identity.
- An administrator requests the identity on the Identities page: a name, scopes (for example
ingest:writeandstatus:read) and an optional IP allow list. - A second person outside the requester’s control chain approves it on the Approvals page.
- The requesting administrator issues a bootstrap code. It is valid for 24 hours, shown once, and works only while the identity holds no certificate.
3. Get a certificate with reindeerctl
Section titled “3. Get a certificate with reindeerctl”The key is generated on the machine and never leaves it.
export REINDEER_SERVER=https://your-cell.example.trreindeerctl keygen -key uploader.keyREINDEER_BOOTSTRAP_CODE=<code> reindeerctl bootstrap -ca server-ca.pem -key uploader.key -out uploader.crtThe certificate is valid for seven days. Renew it from a timer before it expires:
reindeerctl renew -cert uploader.crt -key uploader.key -out uploader.crt4. Upload a first batch
Section titled “4. Upload a first batch”A batch is an NDJSON file with one JSON record per line. In this example the records are orders:
{"order_id": "o-5531", "buyer_id": "u-77", "placed_at": "2026-10-07T09:12:00Z", "total": 1840}export REINDEER_CERT=uploader.crt REINDEER_KEY=uploader.key REINDEER_CA=server-ca.pemreindeerctl session open -partition orders -mode initial -id /order_id -author /buyer_id -ts /placed_at -ts-format rfc3339reindeerctl dry-run -session <session> orders.ndjsonreindeerctl upload -session <session> -n 1 -zstd orders.ndjsonreindeerctl session commit <session>The pointers name each record’s id, owner and time; the time format may be rfc3339, unix, unix_ms or twitter. Without pointers reindeerctl assumes the tweet format (/id_str, /user/id_str, /created_at, twitter). The commit returns a signed receipt.
5. Read and verify
Section titled “5. Read and verify”reindeerctl changes -cursor head -limit 100reindeerctl audit keysKeep the public keys printed by audit keys outside the cell; you verify receipts and erasure certificates against them. See Audit and verification.