Skip to content
Sterling Ivey edited this page Sep 23, 2026 · 2 revisions

Haldir

Governance for AI agents: scoped sessions with spend caps, an encrypted secrets vault, a tamper-evident audit log, and an MCP policy proxy. Python + Flask, SQLite or Postgres, MIT.

The differentiator is not logging — it is proof. Every action goes into an RFC 6962 Merkle tree with Ed25519 Signed Tree Heads, so an auditor can verify offline that the history was not edited. The same primitive Certificate Transparency uses for WebPKI.

New here? Start with the README.


Guides

Try it A one-file demo binary, no Python needed — or the three-probe fixture that ships with the package. No account.
CLI reference Every command, its flags, and which ones support --json.
Self-hosting Docker Compose, Postgres, the configuration to deploy.
How it works The architecture, briefly.
Threat model What it defends against, and — the useful half — what it does not.
Security How to report something.
Contributing
Changelog

Quick answers

What does it actually do?

Your agent talks to Haldir instead of directly to its tools. Every call is checked against the session's scopes and spend cap, logged into the hash chain that the tool call cannot be made without, and only then forwarded upstream. Four parts: Gate (sessions and permissions), Vault (secrets the agent never holds), Watch (the audit trail), Proxy (the enforcement point).

Do I need Docker?

No. haldir serve runs a complete instance on SQLite with nothing installed:

pip install haldir
haldir serve

Can I verify the audit trail myself, without trusting the server?

Yes. haldir audit tree-head gives you the signed root, haldir audit prove <entry> gives you an inclusion proof, and haldir audit verify-proof checks it locally, against a tree head you already hold.

Where is the API reference?

On any instance you are running: /docs and /openapi.json.


Why this wiki is short

The documentation lives in the repository, not here — so it is versioned with the code it describes and reviewed in the same pull request that changes it. A wiki page and a source file describing the same thing is exactly the drift this project keeps finding elsewhere.

This page is an index. If something is missing, the fix is a pull request against the repository, and this page should point at it.

Clone this wiki locally