sessionpipe

An open protocol for what your coding agents are doing.

One install hooks Claude Code, Codex, Gemini CLI, Antigravity and more. Every event is filtered to a privacy tier you choose per destination, secrets are removed on your machine, and it goes to your server, to a file, or nowhere at all.

npx sessionpipe install

Get started · Read the protocol · Source on GitHub

sessionpipe is the missing wire between coding-agent hooks and whatever you want to build on them: a presence board, an activity feed, memory across sessions, a permission prompt you can answer from your phone. Claude Code hooks, Codex hooks, Gemini CLI hooks and Antigravity hooks become one vocabulary of session events, on your terms.

How it fits together

Adapters are the only vendor code. Core owns access, state and transport: what leaves, at which tier, in what order. Interpretation belongs to receivers.

HARNESSESADAPTERSCORESINKS Claude CodeCodexGemini CLIAntigravityCursorCopilot CLIDroid · Kiro · OpenCode one file eachhook stdin → eventstranscript readerfacts: title, url,model, accountthe only vendorcode in the tree normaliseULID, seq, session blockfilter to a tierallowlist per type, per sinkredactsecrets@1 always · pii@1 opt-inoutboxappend-only JSONL, cursor per sinkmoves only on a 2xx file · stdout no server at allsessionpipe-receiver your laptopspacesheep.dev tier 2any HTTPS receiver OTLP too control back: answer a permission, queue a message for the next turn
Harnesses → one adapter each → core (normalise, filter, redact, outbox) → any number of sinks. Control flows back.

Four tiers, chosen per sink

A sink is configured at a tier; the receiver's well-known file declares its maximum; the lower wins. Filtering is an allowlist per event type, never a denylist.

TierWhat leavesGood for
0 presenceSession id, state and timing, machine, folder, repo, branch, model, title, link; the kind of attention neededA board: working / needs you / done
1 actions+ tool names, durations, ok/error, file paths, the attention message, subagents, compactionsAn activity feed
2 conversation+ your prompts and the assistant's text, redactedMemory, search, recaps
3 full+ tool input and output, thinking, raw hook linesFull replay on a receiver you own

The secrets ruleset runs above tier 0 and cannot be turned off. PII reduction is a second, opt-in pass. The privacy spec.

The six moments every harness fires

session.startedturn.startedtool.started · endedattention.neededturn.endedsession.ended tier 0 · startup, resumetier 0 · a prompt went intier 1 · name, ms, oktier 0 · "needs you"tier 0 · stop, interrupttier 0 · four harnesses never say tier 2 adds turn.transcript after each turn; tier 3 adds tool input and output
The protocol carries facts and timestamps, never a verdict: "stale" and "done" are a receiver's readings.

No server needed to see it

sessionpipe tail follows the local outbox. This is what tier 1 looks like:

00:41:02 claude-code 8c13… session.started source=startup ~/spacesheep main 00:41:09 claude-code 8c13… turn.started prompt_chars=61 00:41:11 claude-code 8c13… tool.started Read 00:41:11 claude-code 8c13… tool.ended Read ok 38ms 00:41:14 claude-code 8c13… tool.started Bash 00:41:16 claude-code 8c13… tool.ended Bash ok 1830ms 00:41:31 claude-code 8c13… attention.needed permission Bash "git push origin …"

Who already receives

sessionpipe-receiver

The reference receiver: one process, JSONL files, a page you can answer from a phone. npx sessionpipe-receiver, or Docker.

spacesheep.dev

Sessions, memory and recaps for people who run agents all day. Tier 2, with control.

Yours

Serve /.well-known/sessionpipe and one POST route, pass the conformance suite, and list it.

Three promises

No telemetry

sessionpipe reports to the sinks you configured and to nobody else. This site has no analytics.

Secrets never leave

Redaction runs on your machine, before the outbox, on every string above tier 0.

Your server or none

A file, stdout, the reference receiver on your laptop, or any HTTPS endpoint that speaks the protocol.

Apache-2.0 code, CC BY 4.0 spec, DCO, no CLA. Pre-release: see the roadmap.

Questions people ask

What is sessionpipe?

An open protocol, and a small client, that turns the hooks coding agents already fire (Claude Code, Codex, Gemini CLI, Antigravity, Cursor, Copilot CLI and more) into one uniform stream of session events: started, working on a tool, needs you, ended. You choose per destination how much leaves your machine.

Does it work with Claude Code hooks?

Yes. sessionpipe install writes Claude Code's SessionStart, UserPromptSubmit, PreToolUse, PostToolUse, PermissionRequest, Notification, Stop, Subagent and Compact hooks into every config dir on the machine, and maps them to protocol events. Codex hooks, Gemini CLI hooks and Antigravity hooks work the same way.

What are the privacy tiers?

Tier 0 is presence (session state, timing, folder, model, title). Tier 1 adds tool names, durations and file paths. Tier 2 adds your prompts and the assistant's text. Tier 3 adds tool input and output. A sink is configured at a tier; the receiver declares its maximum; the lower wins. Secrets are redacted on your machine above tier 0, always.

Do I need a server?

No. sessionpipe tail follows the local outbox with no sink configured. When you want a receiver, run the reference one on your laptop, point at any HTTPS endpoint that speaks the protocol, or use a hosted receiver such as spacesheep.

Is there telemetry?

None. The client reports only to the sinks you configure, this website has no analytics or cookies, and the optional version check is a plain read of the npm registry that you can turn off.

Who maintains it, and under what license?

Michael Makarov, with a written path to more maintainers. Code is Apache-2.0, the specification is CC BY 4.0, contributions are under the Developer Certificate of Origin with no CLA.