Getting Started
Install canton-deploy​
Work from your Daml project root, the directory containing daml.yaml or the multi-package.yaml root.
Add canton-deploy to components:
components:
- damlc:3.5.2
- daml-script:3.5.2
- oci://ghcr.io/lync-world/canton-deploy:0.2.2
DPM does not allow sdk-version and components: in the same file; use components: and list damlc / daml-script next to canton-deploy if you need to pin them.
Then install everything the project declares:
dpm install package
On first install, DPM pins the component by digest and rewrites the line to:
oci://ghcr.io/lync-world/canton-deploy:0.2.2@sha256:…
This is expected; leave the pinned reference in place.
You can add and pin the component in one step:
dpm add component oci://ghcr.io/lync-world/canton-deploy:0.2.2
dpm install package
dpm add component accepts "<name>:<version>", oci://<reference>, or a local path object. For GHCR you must use the oci:// form. The short form canton-deploy:0.2.2 resolves against Digital Asset's component registry and will work once canton-deploy is published there.
Verify the installation:
dpm canton-deploy --help
Start Your LocalNet Participant​
For LocalNet, add canton-open-source to components (for example canton-open-source:3.5.17), run dpm install package, then start the sandbox:
dpm sandbox --ledger-api-port 5001 --admin-api-port 5002 --json-api-port 7575
It takes about 30 seconds and prints Canton sandbox is ready. Leave it running in its own terminal.
The default LocalNet ports are:
| API | Default Port |
|---|---|
| Admin API | 5002 |
| Ledger API | 5001 |
| JSON API | 7575 |
Initialize canton-deploy​
From the project root, in another terminal:
dpm canton-deploy init
dpm canton-deploy status --network localnet
dpm canton-deploy deploy --network localnet
init writes canton-deploy.config.js with one profile per network. The default upload path is ledger. It asks which profiles to add alongside LocalNet (DevNet, TestNet, and MainNet), then whether to accept the defaults for each. Answer No to enter host, ports, TLS, upload path, token source, grpcAuthority, and synchronizerId by hand.
For DevNet, init also offers to fetch the JWT through OAuth2 client credentials (for example Auth0 M2M), and to set up an SSH port forward to a remote Docker Compose validator. See Authentication and Remote Validators.
Defaults:
| LocalNet | TestNet | MainNet | |
|---|---|---|---|
| Host | localhost | testnet-validator.example.com (placeholder) | mainnet-validator.example.com (placeholder) |
| Ports | Admin 5002, Ledger 5001, JSON 7575 | Ledger and JSON 443 | Ledger and JSON 443 |
| TLS | Off | On | On |
| Upload path | ledger | ledger | ledger |
| Vet on upload | On | Off | Off |
| Token | LocalNet HMAC | tokenFile: ./.tokens/testnet.jwt | tokenCommand (Vault example) |
| Parties / users | Alice, Bob / ledger-api-user | None | None |
Replace the TestNet and MainNet placeholders with your validator's details before deploying.
The LocalNet HMAC JWT uses an unsafe development secret and is intended only for a local sandbox. Other networks need an explicit JWT; see Authentication.
Using canton-deploy with Claude​
A Claude skill for canton-deploy is published in the LYNC plugin marketplace. With it installed, asking Claude to deploy a Daml package to Canton, set up a validator profile, or debug a failed upload gets answers built on dpm canton-deploy rather than hand-rolled API calls.
claude plugin marketplace add LYNC-WORLD/claude-plugins
claude plugin install canton-deploy@lync
In the Claude desktop app: Customize → Plugins → Add marketplace → https://github.com/LYNC-WORLD/claude-plugins.