CLI Reference
Command reference for the two CLI surfaces: sevorix, which manages the daemon, policies, sessions, and hub interaction; and sevsh, the guarded shell an agent is given in place of a raw one.
Conventions
Commands and flags marked (pro) exist only in pro builds. A Lite binary's --help output simply omits them — it does not list them as unavailable — so if a command documented here is missing from your build, check which edition you installed.
These environment variables apply across commands:
| Variable | Used by | Description |
|---|---|---|
SEVORIX_PORT | sevsh, integrations | Connect directly to this port, overriding all session lookup. |
SEVORIX_SESSION | sevsh, integrations | Connect to the session with this name. |
SEVORIX_SESSION_TOKEN | sevorix session, sevsh | The per-session secret for session-control endpoints. Normally read from the session metadata file automatically. |
SEVORIX_HUB_URL | sevorix hub | Hub server URL. Equivalent to --hub-url. |
SEVORIX_BIND_ADDR | daemon | Bind address for the daemon. Defaults to loopback. |
SEVORIX_ALLOWED_WS_ORIGINS | daemon | Extra exact origins permitted to open the Observatory's WebSocket. |
If neither SEVORIX_PORT nor SEVORIX_SESSION is set and exactly one session is running, it is used automatically. Both are stripped from child processes after resolution, so an agent cannot rebind itself to a less restrictive session.
sevorix
sevorix start
Starts the daemon in the background. By default it starts both the Sevorix proxy and the eBPF daemon.
| Flag | Description |
|---|---|
--name <NAME> | Session name. Defaults to a random UUID. |
--port <PORT> | Port to listen on. Defaults to the first free port from 3000. |
--roles <A,B> | Comma-separated list of roles to load. Restricts the daemon's role set; a policy reload cannot widen it afterwards. |
--role <ROLE> (pro) | Initial active policy role for this session. |
--watchtower-only | Start only the proxy, with no eBPF monitoring. |
--ebpf-only | Start only the eBPF daemon, with no proxy. |
sevorix start
sevorix start --name my-project --port 3001 --role developerStartup runs a pre-flight configuration check through the same code path the daemon itself loads from, so a configuration that passes the check cannot then be rejected by the daemon. A policy that fails to load is fatal rather than skipped — starting anyway would present as a working daemon that silently enforces less than you configured.
The command prints the Observatory's URL, including the ?token= parameter that authenticates its session-control buttons.
sevorix stop
Stops the daemon.
| Flag | Description |
|---|---|
--name <NAME> (pro) | Stop a specific session by name. Defaults to stopping all. |
Nothing is signalled that has not been positively identified as a Sevorix process. A PID file outlives a daemon that crashed or was killed, and the OS recycles PIDs, so stop verifies the process at the recorded PID before sending a signal. A recycled or vanished PID is reported as "not running", the stale files are removed, and the reason names what the PID turned out to be.
sevorix restart
Stops and restarts the daemon. Takes no flags.
sevorix status
Shows daemon status, the active enforcement tier, the Observatory's URL, and whether the tier was degraded from what you configured.
| Flag | Description |
|---|---|
--name <NAME> (pro) | Show a specific session. Defaults to all. |
A DEGRADED marker means the Advanced tier was requested but the running kernel cannot provide it. The /health probe runs only after process identity is confirmed, so "running but unresponsive" can never be reported about somebody else's process.
sevorix run
Runs the daemon in the foreground. Useful for debugging.
| Flag | Description |
|---|---|
--roles <A,B> | Comma-separated list of roles to load. |
A foreground session writes the same metadata a backgrounded one does, so sevsh and the sevorix session commands can discover its port and token.
sevorix validate
Evaluates a command string against your policies without running it, and prints a JSON verdict.
| Argument / flag | Description |
|---|---|
<COMMAND> | The string to evaluate. Positional, required. |
-r, --role <ROLE> | Role to evaluate under. |
-C, --context <CONTEXT> | Shell, Network, Syscall, Mcp, Inbound, or All. Defaults to Shell. |
sevorix validate "DROP TABLE users" -r admin -C Shell{
"command": "DROP TABLE users",
"verdict": "BLOCK",
"lane": "RED",
"reason": "...",
"block_reason": "...",
"confidence": 0.0,
"context": "Shell"
}Exits 1 on BLOCK and 0 otherwise, so it can be used directly in a script. A policy load failure is fatal rather than ignored — scanning against a partially loaded policy set would print a confident ALLOW for a command the missing policy was written to block.
This is the one caller that skips role reference validation: it answers a one-shot question about one role and will not exit over an unrelated role's dangling policy reference.
sevorix config
| Command | Description |
|---|---|
config check | Parses every policy and role file, reports validation errors, and warns about Allow policies broad enough to disable a role. |
config list-builtins (pro) | Lists the compile-time built-in policies, which are always active and cannot be overridden. |
sevorix session
Session control. These commands authenticate with the per-session token, read automatically from ~/.local/state/sevorix/sessions/<name>.json or from SEVORIX_SESSION_TOKEN.
| Command | Description |
|---|---|
session list | List all running sessions. |
session set-role <ROLE> | Set the active policy role for the session. |
session kill | Atomically kill every agent process in the session's cgroup tree. |
session freeze | Suspend every agent process in the session's cgroup without killing it. |
session unfreeze | Resume a frozen session. |
session reload | Reload policies and roles from disk without restarting. |
Every one of these except session list takes --name <NAME>, which is required when more than one session is running.
session kill reports what actually happened
A 2xx response does not imply success. The daemon confirms the outcome against the kernel — polling the cgroup for populated 0 — rather than trusting the helper's exit code, and sevorix session kill exits non-zero and prints the per-session reason and remedy on anything short of a full kill. Only confirmed-dead sessions leave the active session list: a survivor stays registered, because deregistering it would remove your only handle on a live, possibly compromised agent.
sevorix logs
Session traffic logs, stored as JSONL under ~/.sevorix/logs/.
| Command | Flags | Description |
|---|---|---|
logs list | --session <PREFIX> | List log files with metadata. |
logs tail | --session <ID>, -n <N> (default 20), --follow | Print the last N events, optionally streaming new ones. |
logs show <EVENT_ID> | — | Find and print a single event by id across all logs. |
logs stats | --session <ID> | Aggregate statistics for a session log. |
Where --session is optional, it defaults to the most recently modified log.
sevorix logs export (pro)
Exports events to an external destination.
| Flag | Description |
|---|---|
--destination <DEST> | splunk, datadog, cloudwatch, elastic, sentinel, gcp, syslog, webhook, or file. Required. |
--output <URL|PATH> | Endpoint URL, or output file path for file. Required. |
--format <FMT> | ocsf, cef, or json (default). File destination only. |
--session <ID> | Export one session. Defaults to all. |
--since <RFC3339> | Export events after this timestamp. |
--until <RFC3339> | Export events before this timestamp. |
--dry-run | Print what would be sent without sending it. |
sevorix logs verify (pro)
Verifies the tamper-evident receipt signatures in a log file.
| Argument / flag | Description |
|---|---|
[LOG_FILE] | Path to the JSONL log. Defaults to the most recent session log. |
--pubkey <BASE64> | Override the public key. Defaults to ~/.sevorix/signing.key. |
sevorix hub
Client for the Sevorix Hub policy registry. The auth token is stored at ~/.config/sevorix/hub_token. Every subcommand accepts --hub-url <URL> (or SEVORIX_HUB_URL).
| Command | Description |
|---|---|
hub register | Create an account. -e/--email, -p/--password; prompts if omitted. |
hub login | Authenticate and store a token. Same flags as register. |
hub logout | Remove the stored token. |
hub status | Show authentication status. |
sevorix hub push
| Flag | Description |
|---|---|
-n, --name <NAME> | Artifact name. Required. |
-v, --version <VER> | Artifact version, e.g. 1.0.0. Required. |
-f, --file <PATH> | Policy JSON file to upload. Required. |
-d, --description <TEXT> | Optional description. |
-t, --tag <TAG> | Tag. Repeatable. |
--artifact-type <TYPE> | artifact (default) or set. |
--dep <NAME@VERSION> | Declare a dependency. Repeatable. |
--visibility <VIS> | public (default), private, or draft. |
sevorix hub pull
| Argument / flag | Description |
|---|---|
<NAME> <VERSION> | Artifact to pull. Positional, required. |
-o, --output <PATH> | Write to a file. Prints to stdout if omitted. |
--allow-executable | Permit pulling artifacts containing Executable policies. |
--allow-executable is a real decision
An Executable policy runs an arbitrary command against scanned content. Pulling one from a registry means running someone else's code on your machine, which is why it requires an explicit opt-in rather than being permitted by default.
sevorix hub search
| Flag | Description |
|---|---|
-q, --query <TEXT> | Search name and description. |
-t, --tag <TAG> | Filter by tag. |
-l, --limit <N> | Maximum results. Default 20. |
sevorix hub yank / unyank
Both take <NAME> <VERSION> positionally. yank additionally accepts -r/--reason <TEXT>.
sevorix integrations
Routes an AI coding tool's shell commands through sevsh.
| Command | Description |
|---|---|
integrations list | List available integrations. |
integrations status [NAME] | Show status for one integration, or all. |
integrations install <NAME> | Install an integration, verifying prerequisites first. |
integrations uninstall <NAME> | Uninstall an integration. |
integrations start <NAME> [-- ARGS...] | Launch the tool under Sevorix. Anything after -- is forwarded to the tool. |
integrations start also accepts:
| Flag | Description |
|---|---|
--session <NAME> (pro) | Attach to a named Sevorix session. |
--accumulate (pro) | Stream the session's stdin/stdout to the context API, so the Jury and other consumers can use session history. |
sevorix integrations start claude
sevorix integrations start claude --session my-project
sevorix integrations start claude -- --resumeNames are matched loosely — claude and "Claude Code" both work. Manifests and backups are stored in ~/.sevorix/integrations/.
sevorix ca
TLS interception CA management.
| Command | Description |
|---|---|
ca print | Print the CA certificate PEM to stdout, for piping into trust-store tooling. |
ca path | Print the path to the CA certificate file. |
ca regenerate | Regenerate the CA certificate and key. Invalidates every previously issued leaf certificate. |
sevorix prime
Prints a context primer for an AI agent, intended to be piped into the agent's context.
| Argument | Description |
|---|---|
<AGENT_TYPE> | policy-manager (pm) or guarded-agent (guard). |
sevorix hooks (pro)
Fires external commands on policy lifecycle events. Hook definitions live in ~/.sevorix/hooks/<id>.json.
| Command | Description |
|---|---|
hooks list | List configured hooks. |
hooks validate | Validate hook JSON files without starting the server. |
hooks test <ID> | Fire a hook with a dummy context. |
hooks new | Create a hook. |
hooks update <ID> | Update an existing hook's fields. |
hooks remove <ID> | Remove a hook. --force skips confirmation. |
hooks new and hooks update share these flags:
| Flag | Description |
|---|---|
--id <ID> | Hook id (new only; update takes it positionally). |
--event <EVENT> | pre_analyze, post_analyze, pre_proxy, post_proxy, pre_jury, post_jury, or pre_log. |
--command <CMD> | Shell script path or inline shell command. |
--timeout <MS> | Timeout in milliseconds. Default 5000. |
--on-error <MODE> | continue (default) or block. |
--output <PATH> | Where to write the hook JSON (new only). |
sevorix jury (pro)
Manages the Jury of Rivals multi-LLM consensus engine.
| Command | Description |
|---|---|
jury status | Show current config and active state. |
jury enable / jury disable | Turn the jury on or off. |
jury list | List configured members. |
jury add <JSON|PATH> | Add a member from inline JSON or a JSON file. |
jury remove <NAME> | Remove a member by name. |
jury set-quorum <MODE> | majority, unanimous, or any. |
jury set-on-error <ACTION> | allow or block — what happens if a member errors. |
jury test <PAYLOAD> | Dry-run a payload through the current configuration. |
sevorix jury add '{"provider": "anthropic", "api_key": "sk-..."}'
sevorix jury set-quorum majority
sevorix jury set-on-error blocksevorix models (pro)
Manages prompt-injection classifier models for MlClassifier policies.
| Command | Description |
|---|---|
models list | List known and installed models. |
models pull <NAME> | Download a model into ~/.sevorix/models/<NAME>/. |
models pull accepts --with-policy, which additionally writes the model's companion policy into ~/.sevorix/policies/ and wires it into the default role if that role exists.
Model artifacts are pinned by SHA-256 and exact byte size, verified at download and again at load. A mismatch fails closed and there is no bypass flag: a tampered classifier that scores every injection as benign is indistinguishable from a working one at runtime, so an unverifiable artifact is refused rather than trusted.
sevorix receipt (pro)
Ed25519-signed, tamper-evident audit receipts.
| Command | Description |
|---|---|
receipt pubkey | Print the current signing public key. |
receipt rotate-key | Rotate the signing keypair. Backs up the old key; restart the daemon to apply. |
receipt verify <LOG_FILE> | Verify all receipts in a log file. --pubkey <BASE64> overrides the key. |
sevsh
sevsh is the guarded shell. Before running any command it submits it to the daemon for a verdict: ALLOW runs it normally, BLOCK denies execution and exits.
# Interactive
sevsh
# A single command
sevsh -c "rm -rf /"
# Bound to a named session
SEVORIX_SESSION=my-project sevsh -c "echo hello"
# A script
sevsh ./deploy.sh arg1 arg2sevsh accepts the bash invocation forms it stands in for — -c, a script path, positional arguments, and the common set options — so it can be bind-mounted over /bin/bash without breaking callers that expect bash's interface.
Flags
| Flag | Description |
|---|---|
-p, --publish <HOST:CONTAINER> | Publish a port mapping through the sandbox. Repeatable. |
--no-proxy | Do not set proxy environment variables for the child. |
--no-sandbox | Disable sandbox isolation. |
--accumulate (pro) | Stream stdin/stdout to the context API so the Jury and other consumers can access session history. Sets SEVSH_ACCUMULATE, so nested sevsh invocations inherit it. |
--source <LABEL> (pro) | Source label for context chunks, e.g. claude-code. Only valid with --accumulate. |
Internal flags
These exist for the agent launcher and integrations to call, and are documented only so their appearance in a process list is not mysterious. They are not for interactive use.
| Flag | Purpose |
|---|---|
--agent-exec | Execs a target directly inside the sandboxed network namespace with inherited stdio, skipping scanner validation and output capture. Used to namespace an agent binary's own traffic, as distinct from its shell children, which take the normal validated path. |
--mcp-exec <SERVER_NAME> | Interposes on a local stdio-transport MCP server: runs it as a child, relays its stdin/stdout, and validates each tools/call request against Mcp policies before forwarding. |
--internal-sandbox | Internal re-entry point used when constructing the sandbox. |
Session binding
sevsh resolves which daemon to talk to in this order: SEVORIX_PORT, then SEVORIX_SESSION, then — if exactly one session is running — that session.
All three of SEVORIX_PORT, SEVORIX_SESSION and SEVORIX_SESSION_TOKEN are stripped from any child environment after resolution. The child is the agent being sandboxed, and the token authorizes killing the session that supervises it; leaving either in place would let the guarded process rebind itself to a less restrictive session or terminate its own supervisor.
See also
- Install — installing the binaries these commands come from.
- File Locations — where those binaries, and the files these commands read and write, live.
- Policy Format — what
validate,config checkandsession reloadare operating on.