straza
Straza client: enroll this machine, wire the hooks and decide each tool call
Commands
- straza connect: Connect your own account to an MCP server; no server lists your connections
- straza daemon: Keep the session fresh and apply kill-switch pushes
- straza disconnect: Remove your own connection to an MCP server
- straza doctor: Diagnose enrollment, connectivity, snapshot, hook wiring, and the audit spool
- straza enroll: Log in via the OIDC device flow and enroll this device (--headless: an AI agent with no browser)
- straza exec: Run a command through Straza policy, for an agent that has no hooks
- straza hook: Hook entrypoint: normalize a harness payload and decide (reads stdin)
- straza install: Write hook wiring for Tier-1 harnesses (user mode, or --managed system layout)
- straza keygen: Generate the local Ed25519 key an AI agent enrolls with headless
- straza logs: Print the client error log (hook/spool/drain failures; never payload content)
- straza mcp: Serve the Straza MCP gateway to this harness over stdio (
straza installregisters it) - straza status: Show enrollment and session status
- straza trace: Decision journal and debug trace (content-free): on, off, status, show
- straza uninstall: Remove Straza hook wiring from harness settings
- straza version: Print version information