Repository navigation
Home
Governance for AI agents: scoped sessions with spend caps, an encrypted secrets vault, a tamper-evident audit log, and an MCP policy proxy. Python + Flask, SQLite or Postgres, MIT.
The differentiator is not logging — it is proof. Every action goes into an RFC 6962 Merkle tree with Ed25519 Signed Tree Heads, so an auditor can verify offline that the history was not edited. The same primitive Certificate Transparency uses for WebPKI.
New here? Start with the README.
| Try it | A one-file demo binary, no Python needed — or the three-probe fixture that ships with the package. No account. |
| CLI reference | Every command, its flags, and which ones support --json. |
| Self-hosting | Docker Compose, Postgres, the configuration to deploy. |
| How it works | The architecture, briefly. |
| Threat model | What it defends against, and — the useful half — what it does not. |
| Security | How to report something. |
| Contributing | |
| Changelog |
What does it actually do?
Your agent talks to Haldir instead of directly to its tools. Every call is checked against the session's scopes and spend cap, logged into the hash chain that the tool call cannot be made without, and only then forwarded upstream. Four parts: Gate (sessions and permissions), Vault (secrets the agent never holds), Watch (the audit trail), Proxy (the enforcement point).
Do I need Docker?
No. haldir serve runs a complete instance on SQLite with nothing installed:
pip install haldir
haldir serveCan I verify the audit trail myself, without trusting the server?
Yes. haldir audit tree-head gives you the signed root, haldir audit prove <entry> gives you an inclusion proof, and haldir audit verify-proof checks it
locally, against a tree head you already hold.
Where is the API reference?
On any instance you are running: /docs and /openapi.json.
The documentation lives in the repository, not here — so it is versioned with the code it describes and reviewed in the same pull request that changes it. A wiki page and a source file describing the same thing is exactly the drift this project keeps finding elsewhere.
This page is an index. If something is missing, the fix is a pull request against the repository, and this page should point at it.