Terminal and harkctl
Advanced. You never need the terminal to use your bots. It's there for people who like to look under the hood: everything in the app can also be done here, plus a few things that are deliberately terminal-only, such as backing up a wallet's private key.
Turn on the Advanced switch to see the server's Terminal page. It has the SSH command to copy, your SSH keys, the server's host key fingerprints and this command list.
Signing in with SSH
Your server accepts SSH keys only. There is no password to guess or leak. You sign in as the ubuntu user (ssh ubuntu@<your server's address>); signing in as root is turned off. Commands that need root use sudo.
- Add your public key on the Terminal page (Add an SSH key). Paste the public half, the line that starts with
ssh-ed25519orssh-rsa, usually from a file ending in.pub. Never paste a private key; the page refuses one. - Copy the SSH command from the top of the Terminal page and run it in your own terminal.
- Check the host key the first time (below).
You don't need a key at checkout; add one whenever you want terminal access. Keys you add on the Terminal page replace each other as a set; keys added on the server with harkctl ssh-keys add are kept separately.
Create an SSH key
An SSH key comes in two halves: a private key that stays on your computer, and a public key you give to your server. If you already have one, the public half is in a file ending in .pub in the .ssh folder of your home directory.
To make a new one, open a terminal (on Windows 10 or 11, PowerShell) and run:
ssh-keygen -t ed25519 -C "you@laptop"Press Enter to keep the default file, and set a passphrase if you want one. Then show the public half:
cat ~/.ssh/id_ed25519.pubOn Windows PowerShell: Get-Content $env:USERPROFILE\.ssh\id_ed25519.pub. Copy the single line it prints, starting ssh-ed25519, and paste it at checkout or on the Terminal page. Never share the file without .pub: that is your private key.
Check the host key fingerprint
The first time you connect, SSH shows the server's host key fingerprint and asks whether to trust it. It looks like SHA256: followed by a string of letters and numbers.
Compare it with the Host keys on the Terminal page (ED25519 and ECDSA). Answer yes only if it matches one of them exactly. If it doesn't match, don't connect, and contact us: something is between you and your server.
The page also shows the bot agent's fingerprint. On the server, harkctl agent fingerprint should print the same one.
harkctl
harkctl is the command-line tool on every bots server. It talks to the bot agent on the server, so the same rules apply as in the app: going live and moving money need your PIN, and limits are enforced by the bot.
<bot> is sniper (Solana Block-0 Sniper) or momentum (Solana Momentum Sniper). harkctl needs root, so run it with sudo, for example sudo harkctl status. Run harkctl --help, or harkctl <command> --help, for the full options of any command.
Things that work only here
- Importing and exporting a wallet's private key. Keys never go through the web. Export asks for your PIN.
- The withdrawal allowlist. Addresses added with
harkctl withdraw-allowlist addare active at once, because only someone signed in to your server can add them. Addresses saved in the app wait 24 hours instead. - Installing or rolling back bot versions, and managing SSH keys and support access from the server itself.
Config from the terminal
harkctl config edit opens the running config in your editor and saves it as a new version; validate, diff and apply let you work from a file. Every save, from the web, support or the terminal, is a version, and harkctl config history shows who saved each one and from where. The web app sees terminal changes straight away. The settings are listed in the Solana Block-0 Sniper and Solana Momentum Sniper references.
Command reference
Bots
| Command | What it does | Notes |
|---|---|---|
harkctl status | Every bot on this server: version, running or not, schedule, licence, and the server's SSH host keys. | |
harkctl start <bot> | Start a bot (sniper or momentum). | |
harkctl stop <bot> [--sell-all] | Stop a bot. Open positions stay open; with --sell-all it sells every open position first, then stops. | |
harkctl restart <bot> | Stop and start a bot. Positions stay open. | |
harkctl pause <bot> | Pause buying. Open positions are still managed and sold. | |
harkctl resume <bot> | Resume buying. | |
harkctl logs <bot> [-f] [-n <lines>] [--search <search>] | A bot's log: -f keeps following it, -n sets how many lines (100 by default), --search shows only lines containing the text. |
Config
| Command | What it does | Notes |
|---|---|---|
harkctl config show <bot> [--version <version>] | The config the bot is running, or an older saved version. | |
harkctl config edit <bot> [--note <note>] | Open the config in your editor ($EDITOR) and save it as a new version. | |
harkctl config validate <bot> <file> | Check a TOML file against the bot without saving it. | |
harkctl config diff <bot> [file] [--version <version>] | Compare a file, or a saved version, with the running config. | |
harkctl config apply <bot> <file> [--note <note>] | Save a TOML file as the new config. The web sees the new version. | |
harkctl config history <bot> | Every version, who saved it and from where (web, support or terminal). | |
harkctl config rollback <bot> <version> | Save an earlier version again as the newest one. |
Wallet
| Command | What it does | Notes |
|---|---|---|
harkctl wallet list <bot> | The bot's wallets and their balances. | |
harkctl wallet create <bot> <label> | Create a new wallet on this server. | |
harkctl wallet import <bot> <label> | Import a wallet from a private key. The key is read from the keyboard and never shown. | Terminal only |
harkctl wallet export <bot> <wallet> | Show a wallet's private key so you can back it up. | Terminal only · Asks for the PIN |
harkctl wallet use <bot> <wallet> | Choose the wallet the bot trades from. | Asks for the PIN |
harkctl pin set <bot> | Set or change the bot's PIN (asks for the current one when there is one). |
Withdrawals
| Command | What it does | Notes |
|---|---|---|
harkctl withdraw-allowlist list | Addresses withdrawals may go to. | |
harkctl withdraw-allowlist add <address> [label] | Allow withdrawals to an address. Added here, it can be used at once (no 24-hour wait). | Terminal only |
harkctl withdraw-allowlist remove <address> | Remove a withdrawal address. | Terminal only · Also: rm |
Server
| Command | What it does | Notes |
|---|---|---|
harkctl update <bot> [--check] [--force] | Install the release AllenHark published for a bot. --check only says whether there is one; --force allows an older version. | |
harkctl rollback <bot> | Go back to the version of the bot installed before. | |
harkctl licence | This server's licence and what it allows right now. | |
harkctl doctor | Check the connections, the relay and the clock, and say what is wrong. |
Support and access
| Command | What it does | Notes |
|---|---|---|
harkctl support grant <hours> | Let AllenHark support help for this many hours (at most 720). | |
harkctl support revoke | End support access now. | |
harkctl agent fingerprint | The bot agent's key fingerprint. It should match the one on the web Terminal page. | |
harkctl ssh-keys list | SSH public keys allowed to log in. | |
harkctl ssh-keys add <key> | Allow another SSH public key. Keys added here are kept when you change keys on the web. | |
harkctl ssh-keys remove <match> | Remove the SSH key that matches (part of the key or its comment). | Also: rm |
Options for every command
--json | Print machine-readable JSON instead of text. |
--socket <path> | The agent's control socket (default /run/allenhark/harkd.sock, or $HARKCTL_SOCKET). |
