Neural Inverse is Open Source →
DocsCLI Reference

keystone-capture-agent

The headless capture daemon. Records AI coding assistant activity to an encrypted local store.

keystone-capture-agent [COMMAND]

Commands

CommandDescription
(none)Run capture daemon in foreground
inspectView recent captured events in plaintext
exportExport signed JSON bundle
schemaShow event types and field schema
statusShow daemon status and chain health
installInstall as system service (auto-start on login)
uninstallRemove system service
hooksManage AI tool integration hooks
apiRun REST API server for scripts and integrations
streamStream events as JSON Lines (pipe to jq, etc.)
queryQuery events with filters
versionShow version information
helpShow help

Environment Variables

VariableDefaultDescription
KEYSTONE_DATA_DIR~/.keystone-captureData directory for encrypted store and keys
KEYSTONE_LOG_LEVELinfoLog level: debug, info, warn, error
KEYSTONE_HOOK_ADDR127.0.0.1:9193Hook receiver address for AI tool webhooks

inspect

View recent captured events in plaintext.

keystone-capture-agent inspect [OPTIONS]
FlagDefaultDescription
-n50Number of events to show
-action(all)Filter by action prefix (e.g., file, process, shell)

Examples:

# Show last 50 events
keystone-capture-agent inspect

# Show last 200 file events
keystone-capture-agent inspect -n 200 -action file

# Show process detections
keystone-capture-agent inspect -action process

export

Export a signed JSON bundle suitable for auditors and compliance review.

keystone-capture-agent export [OPTIONS]
FlagDefaultDescription
-o- (stdout)Output file path
-pseudonymizefalseReplace usernames with pseudonyms. Note: pseudonymized exports are NOT independently verifiable
-anchorfalseRequest RFC 3161 timestamp from TSA for audit-grade external proof
-tsa-urltimestamp.digicert.comRFC 3161 TSA URL

Examples:

# Export to stdout (pipe to jq for viewing)
keystone-capture-agent export | jq .

# Export signed bundle to file
keystone-capture-agent export -o audit-2026-10.json

# Export with RFC 3161 timestamp anchor
keystone-capture-agent export -o audit.json -anchor

# Export with privacy pseudonymization
keystone-capture-agent export -o audit.json -pseudonymize

Export bundle format:

{
  "version": 1,
  "exported_at": "2026-10-03T12:00:00Z",
  "agent_version": "0.1.0",
  "chain_status": {
    "total_events": 365,
    "head_hash": "f039eca40199acdb...",
    "chain_valid": true
  },
  "signed_data": "base64...",
  "signature": "base64...",
  "public_key": "base64...",
  "events": [...]
}

schema

Print the event type schema — all event categories and their fields.

keystone-capture-agent schema

status

Show daemon status, data directory, chain health, and event counts.

keystone-capture-agent status

Output includes:

  • Data directory path
  • Store initialization state
  • Total events and chain integrity
  • Signing key status
  • Running processes detected

install / uninstall

Manage the system service for auto-start on login.

# Install as launchd (macOS) or systemd (Linux) service
keystone-capture-agent install

# Remove the service
keystone-capture-agent uninstall
PlatformService ManagerService Name
macOSlaunchdcom.neuralinverse.keystone-capture
Linuxsystemd (user)keystone-capture.service

hooks

Manage AI tool integration hooks. Hooks allow Keystone to receive real-time notifications from AI tools.

keystone-capture-agent hooks [SUBCOMMAND]
SubcommandDescription
installInstall hooks for all detected AI tools
uninstallRemove hooks from all AI tools
statusShow hook status for each tool

Supported AI tools:

ToolHook TypeConfig Location
Claude Codesettings.json hooks~/.claude/settings.json
CodexHook config~/.codex/hooks.json
Copilot CLIHook config~/.copilot/hooks
KiroHook config~/.kiro/hooks
CursorExtension hooks~/.cursor/
Gemini CLIHook config~/.gemini/hooks.json
WindsurfExtension hooks~/.windsurf/
ClineVS Code extensionVS Code settings
TraeExtension hooks~/.trae/

api

Run a REST API server for programmatic access.

keystone-capture-agent api [OPTIONS]

This starts the same API server used by the tray UI. See API Reference for all endpoints.

stream

Stream events in real-time as JSON Lines. Useful for piping to jq, log aggregators, or custom tooling.

keystone-capture-agent stream [OPTIONS]

Examples:

# Stream all events
keystone-capture-agent stream

# Stream and filter with jq
keystone-capture-agent stream | jq 'select(.action | startswith("file"))'

# Stream to a file
keystone-capture-agent stream >> events.jsonl

query

Query captured events with filters.

keystone-capture-agent query [OPTIONS]
FlagDescription
--type TYPEFilter by event type (e.g., file.open, process.detected)
--since DURATIONEvents since duration (e.g., 1h, 24h, 7d)
--target PATTERNFilter by target path (substring match)

Examples:

# Query file events from last hour
keystone-capture-agent query --type file --since 1h

# Query events targeting a specific project
keystone-capture-agent query --target /Users/dev/myproject --since 24h

keystone-capture-tray

Desktop menu bar app with web UI.

keystone-capture-tray [FLAGS]
FlagDescription
(none)Run as macOS menu bar tray icon
--windowOpen the web UI directly in a browser/webview

The tray app provides:

  • Menu bar icon with quick status
  • Start/stop capture from the menu
  • Web UI for monitoring, configuration, and audit verification
  • All API endpoints on a local port

keystone-capture-verify

Independent chain verification tool. Can be distributed to auditors — it only needs the export bundle and the public key.

keystone-capture-verify [OPTIONS] <export-file>
FlagDefaultDescription
-expect-key(none)Expected key fingerprint (first 16 hex chars of public key)
-jsonfalseOutput results as JSON
-versionShow version

Verification checks:

CheckDescription
Ed25519 signatureVerifies the signature is valid for signed_data
Data integrityVerifies signed_data matches the events array
Chain linkageVerifies previous_hash → entry_hash continuity
Head hashVerifies head_hash matches the last entry_hash
Key pinningOptionally verifies the public key fingerprint matches -expect-key

What verifiers CANNOT check (requires the HMAC key, which stays on the capture machine):

  • entry_hash derivation (chain_status is the exporter's claim)
  • That events weren't omitted before export

Examples:

# Verify an export bundle
keystone-capture-verify audit-2026-10.json

# Verify with key pinning
keystone-capture-verify -expect-key f039eca40199acdb audit.json

# JSON output for CI/CD integration
keystone-capture-verify -json audit.json | jq .

Was this page helpful?

Last edited