{
    "mode": "man",
    "parameter": "boltctl",
    "section": "1",
    "url": "https://www.chedong.com/phpMan.php/man/boltctl/1/json",
    "generated": "2026-10-05T21:58:44Z",
    "synopsis": "boltctl authorize DEVICE\nboltctl config\nboltctl domains\nboltctl enroll DEVICE\nboltctl forget DEVICE\nboltctl info DEVICE\nboltctl list\nboltctl monitor\nboltctl power",
    "sections": {
        "NAME": {
            "content": "boltctl - control the thunderbolt device manager\n",
            "subsections": []
        },
        "SYNOPSIS": {
            "content": "boltctl authorize DEVICE\nboltctl config\nboltctl domains\nboltctl enroll DEVICE\nboltctl forget DEVICE\nboltctl info DEVICE\nboltctl list\nboltctl monitor\nboltctl power\n",
            "subsections": []
        },
        "DESCRIPTION": {
            "content": "boltctl is the command line interface to interact with boltd, the system daemon that manages\nThunderbolt 3(TM) devices. It can be used to query the state of devices as well as manage\nthem.\n\nDevices can be globally identified via their unique identifier (uuid). All commands that take\na DEVICE identifier expect this unique id.\n\nIf no command is given, it is equivalent to boltctl list.\n",
            "subsections": []
        },
        "OPTIONS": {
            "content": "",
            "subsections": [
                {
                    "name": "--version",
                    "content": "Print version information and exit.\n",
                    "long": "--version"
                },
                {
                    "name": "-U | --uuid {_",
                    "content": "Control how UUIDs are printed. Since they are somewhat sensitive data it is not advisable\nto share them publicly in full length. Instead short or alias can and should be used when\nsharing the output of boltctl.\n\nfull\nPrint all UUIDs in full length.\n\nshort\nTruncate all UUIDs so only the first 13 characters are printed.\n\nalias\nAll UUIDs are replaced by a random string that is derived from the UUID, therefore\nthe devices can be uniquely identified without revealing the original UUID.\n\nN\nIf a integer N is specified, all UUIDs are truncated to only show up to N.\n",
                    "flag": "-U",
                    "long": "--uuid"
                }
            ]
        },
        "COMMANDS": {
            "content": "",
            "subsections": [
                {
                    "name": "authorize [-F | --first-time] DEVICE",
                    "content": "Authorize a currently unauthorized device identified via its unique id (uuid) DEVICE. If a\nkey is stored in the database it will be used, given the security level of the domain\nsupports secure device connection. Use boltctl list to find out the uuid of a device.\n"
                },
                {
                    "name": "-F | --first-time",
                    "content": "Normally, when attempting to authorize an already authorized device boltctl will do\nnothing and return a successful status code. When using this option, the attempt will\nfail and result in a negative exit code if the device is already authorized.\n",
                    "flag": "-F",
                    "long": "--first-time"
                },
                {
                    "name": "config --describe [global|domain|device]",
                    "content": "List global, domain, or all (if nothing is specified) properties. The format is 3 columns:\npermission, name, description. Permission indicates if the property is only readable or can\nalso be written.\n\nconfig KEY [VALUE]\nGet or set, if VALUE is specified, a global property.\n\nconfig <domain|device>.KEY TARGET [VALUE]\nGet or set, if VALUE is specified, a domain or device property, where TARGET is the unique id\nof the domain or the device.\n"
                },
                {
                    "name": "domains [-v | --verbose]",
                    "content": "List all currently active Thunderbolt domains. A Thunderbolt domain represents the\nThunderbolt controller hardware. There will be one domain (and host device) for each\nThunderbolt controller present in the system. The security property shows the security level\nof the controller. If iommu support is active (see the boltd man page) it will be indicated\nby a +iommu suffix for \"secure\" or \"user\" mode, or just plain iommu in case the security\nlevel is \"none\" (sl0). bootacl shows the used and total slots of the boot access control list\n(BootACL) and the content of all non-empty entries. NB: if BootACL is unsupported it will\nshow 0 for both (0/0). The online property shows if the thunderbolt controller is currently\npowered by the firmware. NB: if the controller is currently offline the BootACL list will\nreflect what boltd estimates the list will look like once the controller is back online and\nlocal changes have been synchronized to the controller. This might not be accurate if the\nlist was modified in the meantime, e.g. from a different installation or OS.\n\nenroll [--policy policy] DEVICE\nAuthorize and record the device with the unique id DEVICE in the database. If the domain\nsupports secure connection a new key will be generated and stored in the database alongside\nthe device name and vendor name. The key, if created, will be used in the future to securely\nauthorize the device.\n\n--policy {default | auto | manual}\nSpecify the policy to be used for the newly enrolled device.\n\ndefault\nUse the global default policy of the daemon; this can be changed, but is normally\nalso auto.\n\nauto\nAutomatically authorize this device whenever it is connected.\n\nmanual\nDo not automatically authorize the device; instead require manual authorization via\nboltctl authorize.\n"
                },
                {
                    "name": "forget DEVICE",
                    "content": "Remove the information about the device with the unique id DEVICE from the database. This\nincludes the key, if one was previously generated. If you pass --all instead of the DEVICE\nall devices are removed instead of just one.\n"
                },
                {
                    "name": "info DEVICE",
                    "content": "Display information about the device with the unique id DEVICE.\n"
                },
                {
                    "name": "list [-a | --all]",
                    "content": "List and print information about all connected and stored devices.\n"
                },
                {
                    "name": "-a | --all",
                    "content": "Normally, the only the device type that will be shown is peripherals. Therefore the\ndevice that represents the host itself will be omitted. Using this option will instead\ninclude all device types in the list.\n",
                    "flag": "-a",
                    "long": "--all"
                },
                {
                    "name": "monitor",
                    "content": "Listen for and show changes in connected devices.\n\npower [-t | --timeout seconds] [-q | --query]\nPower up the Thunderbolt controller. If the Thunderbolt controller is not in \"native\nenumeration mode\" it can be completely powered down by the host firmware/BIOS. On supported\nsystems there is an interface to \"force\" power the thunderbolt controller. If supported this\ncommand will request the daemon to do so. The daemon will keep track of all client requests\nand will release the force power override when the last request is released.\n"
                },
                {
                    "name": "-t | --timeout _",
                    "content": "Release the force power request after the specified amount of seconds and exit.\n",
                    "flag": "-t",
                    "long": "--timeout"
                },
                {
                    "name": "-q | --query",
                    "content": "Query the current force power status of the daemon.\n",
                    "flag": "-q",
                    "long": "--query"
                }
            ]
        },
        "AUTHOR": {
            "content": "Written by Christian Kellner <ckellner@redhat.com>.\n\nbolt 0.9.7                                   04/01/2024                                   BOLTCTL(1)",
            "subsections": []
        }
    },
    "summary": "boltctl - control the thunderbolt device manager",
    "flags": [
        {
            "flag": "",
            "long": "--version",
            "arg": null,
            "description": "Print version information and exit."
        },
        {
            "flag": "-U",
            "long": "--uuid",
            "arg": null,
            "description": "Control how UUIDs are printed. Since they are somewhat sensitive data it is not advisable to share them publicly in full length. Instead short or alias can and should be used when sharing the output of boltctl. full Print all UUIDs in full length. short Truncate all UUIDs so only the first 13 characters are printed. alias All UUIDs are replaced by a random string that is derived from the UUID, therefore the devices can be uniquely identified without revealing the original UUID. N If a integer N is specified, all UUIDs are truncated to only show up to N."
        }
    ],
    "examples": [],
    "see_also": [],
    "tldr": {
        "source": "official",
        "description": "Control thunderbolt devices.",
        "examples": [
            {
                "description": "List connected (and authorized) devices",
                "command": "boltctl"
            },
            {
                "description": "List connected devices, including unauthorized ones",
                "command": "boltctl list"
            },
            {
                "description": "Authorize a device temporarily",
                "command": "boltctl authorize {{device_uuid}}"
            },
            {
                "description": "Authorize and remember a device",
                "command": "boltctl enroll {{device_uuid}}"
            },
            {
                "description": "Revoke a previously authorized device",
                "command": "boltctl forget {{device_uuid}}"
            },
            {
                "description": "Show more information about a device",
                "command": "boltctl info {{device_uuid}}"
            }
        ]
    }
}