All endpoints are served on 127.0.0.1:{port} when running keystone-capture-tray --window or keystone-capture-agent api.
Status & Control
GET /api/status
Returns the current agent status, version, event count, and capture state.
Response:
{
"version": "0.1.0",
"capturing": true,
"events": 365,
"uptime": "2h15m",
"data_dir": "/Users/dev/.keystone-capture"
}POST /api/start
Start the capture agent. Begins monitoring AI tool processes and file system activity.
POST /api/stop
Stop the capture agent. Flushes buffers and closes listeners.
Events
GET /api/events
Query captured events with filters.
Query Parameters:
| Parameter | Type | Description |
|---|---|---|
action | string | Filter by action prefix (process, file, shell, network, hook) |
since | string | Time window (1h, 24h, 7d) |
search | string | Search target paths, parameters, IPs |
Response:
{
"events": [
{
"timestamp": "2026-10-03 11:11:48",
"action": "process.detected",
"target": "claude",
"details": { "pid": 2810, "project_dir": "/Users/dev/myproject" }
}
],
"total": 365
}GET /api/export
Export all events as a JSON download.
POST /api/export/save
Save events to a CSV file on disk.
Response:
{
"path": "/Users/dev/.keystone-capture/export-2026-10-03.csv",
"event_count": 365
}Audit Chain
GET /api/audit/chain
Get audit chain entries with total count and integrity status.
Response:
{
"total_events": 365,
"entries": [
{
"sequence": 365,
"action": "process.detected",
"entry_hash": "f039eca40199acdb...90eb83c3",
"previous_hash": "7cd18757b2e9118e...b6505ac3",
"timestamp": "2026-10-03T11:11:48Z"
}
]
}POST /api/audit/verify
Run full cryptographic chain verification. Validates HMAC-SHA256 chain linkage across all entries.
Response (success):
{
"valid": true,
"entries_checked": 365,
"head_hash": "f039eca40199acdb...90eb83c3"
}Response (failure):
{
"valid": false,
"failed_at": 142,
"error": "chain break: expected hash does not match"
}POST /api/audit/prune
Prune old audit records based on retention policy.
Request Body:
{
"retention_days": 30
}Response:
{
"pruned": 120,
"remaining": 245
}Integrations
GET /api/hooks
List all AI tool integrations and their install state.
Response:
{
"hooks": [
{
"name": "claude-code",
"installed": true,
"config": "/Users/dev/.claude/settings.json"
},
{
"name": "gemini-cli",
"installed": false
}
]
}POST /api/hooks/install
Install hooks for all detected AI tools.
POST /api/hooks/install/{name}
Install a specific hook. Supported names: claude-code, codex, copilot-cli, kiro, gemini-cli, cursor, windsurf, cline, trae.
POST /api/hooks/uninstall/{name}
Remove a specific hook.
Projects
GET /api/projects
List detected workspaces where AI agent activity has been captured.
Response:
{
"projects": [
{
"name": "auth",
"path": "/Users/dev/Documents/auth",
"event_count": 292,
"tools": ["claude"]
}
]
}Privacy & Cryptography
GET /api/privacy/status
Get encryption, signing key, PII key, and hardware key status.
Response:
{
"initialized": true,
"pii_key_active": false,
"encryption": "aes-256-gcm",
"signing_key_exists": true,
"signing_key_type": "ed25519",
"hardware_key_available": false,
"data_dir": "/Users/dev/.keystone-capture"
}Settings & Configuration
GET /api/settings
Get current agent configuration.
GET /api/service/status
Check background daemon install and run status.
Response:
{
"installed": true,
"running": true,
"service_type": "launchd"
}POST /api/service/install
Install launchd (macOS) or systemd (Linux) daemon for auto-start on login.
POST /api/service/uninstall
Remove the background daemon.
POST /api/open-data-dir
Open data directory in Finder (macOS) or file manager.
GET /api/open-file
Open a file in the system default application.
Query Parameters:
| Parameter | Type | Description |
|---|---|---|
path | string | File path to open (supports ~ expansion) |
Last edited