STRAZAdocs

straza hook

Hook entrypoint: normalize a harness payload and decide (reads stdin)

On this page

Synopsis

Reads one harness event as JSON on stdin, decides it against the signed policy of this machine’s session, spools the audit record and answers in the harness’s own format. straza install wires it into each harness, so you rarely run it by hand.

An allow exits 0. Codex then gets empty stdout, and Claude Code and the Python SDK get the decision on stdout for a tool call. A deny prints the reason on stderr and exits 2, and Claude Code also reads the decision on stdout. Gemini instead reads every answer, a deny included, as JSON on stdout and ignores the exit code. When the hook cannot decide, it denies.

straza hook [flags]

Options

      --conformance-policy string   decide against this PolicySet file instead of the session snapshot, for conformance runs: no check-in with the server and no audit record
      --harness string              the harness dialect: claude-code, codex, gemini or python-sdk (default: the STRAZA_HARNESS variable, else detected from the harness's environment and the payload)

See also

  • straza: Straza client: enroll this machine, wire the hooks and decide each tool call

Search documentation

Search page titles, commands, and article text.

↑ ↓ Choose resultEnter OpenEsc Close