Skip to main content

flightdeck-connect — the VeriCommand rail

VeriCommand (formerly FlightDeck) is the neutral desk for every AI agent you use: point Claude Code, Cursor, Codex, and Kimi at one board and one hash-chained, tamper-evident record of what they actually did — so "the AI said it did it" and "it happened" stop being the same sentence.

This package is that rail. It provisions the VeriCommand MCP server into the AI coding tools already on your machine, runs governed agent lanes, and verifies signed evidence packs offline.

Is it worth running? The AI that wrote most of VeriCommand assessed the product itself — unedited — at https://vericommand.net/claude.

(The PyPI name, the conductor import package, and every console-script name keep their original spelling on purpose — existing MCP configs and scripts must never break on a rename. VeriCommand is the brand; the rail's wiring is the same.)

After pip install flightdeck-connect you get:

  • flightdeck-connect — detect the AI coding tools on this machine and idempotently provision the VeriCommand MCP server into each (Claude Code project .mcp.json, Cursor mcp.json, codex mcp add, Kimi ~/.kimi-code/mcp.json), profiled by task, chain-recording the provisioning when a board is given.

  • conductor — a stdlib-only HTTP client for the /v1/conductor/* API.

  • conductor-mcp — a stdio JSON-RPC Model Context Protocol server that exposes 49 tools (21 conductor_* + 28 flightdeck_*, scoped at runtime via MCP_TOOL_SET=flightdeck|conductor|all) to MCP-aware agent runtimes (Claude Code, Cursor, Codex, Kimi, VS Code agents). The flightdeck_* family implements the FlightDeck Agent Contract v1 loop — get_handoff → read_exam → prepare_workspace → submit_return.

  • flightdeck-verify — standalone offline evidence-pack verifier. It always checks hashes + chain and reports the detached-signature state; install the optional signature extra to cryptographically verify an Ed25519 seal (exit 0/1/2; --json).

  • flightdeck-gate — pre-merge git gate for verify-gated merges (chain walk + accept-gate conjuncts + reference-transaction guard).

Install

pip install flightdeck-connect

Zero runtime dependencies (pure Python stdlib). Python 3.9+.

Free vs Pro

The rail, the local board, and offline verification are free. VeriCommand Pro ($39) adds cross-vendor drift-compare — point two models at the same task and get a referee on what actually differs — plus the hosted team board. Upgrade at https://vericommand.net/pro.

For cryptographic verification of signed release packs:

pip install "flightdeck-connect[signature]"

Without that optional backend, a present signature is reported as unverified-no-lib and the aggregate does not pass. Unsigned packs remain a legitimate, explicit state.

To make a seal an attribution rather than a self-consistency check, pin the signing key's fingerprint — see Trust anchor below.

Auth

The CLI authenticates one of two ways:

Header Env var Source
X-Agent-Token CONDUCTOR_AGENT_TOKEN Service token issued by /v1/conductor/projects/{id}/agent-tokens. Preferred for agents.
X-JWT-Token CONDUCTOR_USER_JWT A standard FlightDeck access token. Fallback for humans.
export CONDUCTOR_AGENT_TOKEN=cdtr_...
conductor whoami

CLI quickstart

# Probe auth + caller mode
conductor whoami

# Project + task ops
conductor project list
conductor project create --name "FlightDeck delivery"
conductor task list --project <project-id>

# Workflow transition (policy-gated)
conductor transition TASK-0040 \
    --action submit_review --to-state review_ready \
    --actor-member-id <member-id> \
    --reason "tests pass, ruff clean" \
    --evidence gitlab_mr=https://gitlab.com/.../merge_requests/126

# Release pack — download + offline verify
conductor export --project <project-id> --out release.tar.gz
conductor verify release.tar.gz
# -> signature_status: verified | unsigned | untrusted-key |
#                      unverified-no-anchor | unverified-no-lib |
#                      broken | invalid
# -> Exit 0 only for clean verified or explicitly unsigned packs.

conductor --help lists every subcommand. --json on any command gives machine-readable output for scripting; the default is friendly text.

Local board mode

Local board mode is the zero-cloud bridge for IDEs. It operates directly on a filesystem board folder:

<Project Conductor folder>/queue/TASK-*.md

No CONDUCTOR_AGENT_TOKEN or CONDUCTOR_USER_JWT is required.

BOARD="C:/FlightDeck/Board"

conductor --json local list --board "$BOARD"
conductor --json local list --board "$BOARD" --state READY
conductor --json local read TASK-0001 --board "$BOARD"
conductor local handoff TASK-0001 --board "$BOARD"

Create and update packets:

conductor --json local create \
  --board "$BOARD" \
  --title "Audit the installer handoff" \
  --objective "Verify artifacts and append evidence." \
  --owner Codex \
  --reviewer "Claude Code"

conductor --json local signal TASK-0001 \
  --board "$BOARD" \
  --state REVIEW_READY \
  --action submit_review \
  --verdict "Audit completed; report attached." \
  --next "Reviewer checks the evidence and accepts or requests changes."

The board must be on a local-only filesystem path. FlightDeck refuses board writes under OneDrive, Dropbox, Google Drive, iCloud, or Box because locks on one machine cannot protect a second machine from forking the event chain.

MCP server (Claude Code / Cursor / Codex / Kimi)

The conductor-mcp script implements the Model Context Protocol (2024-11-05) over stdio. Sample config snippets:

Claude Code (~/.config/claude/claude_desktop_config.json or project- level .mcp.json):

{
  "mcpServers": {
    "conductor": {
      "command": "conductor-mcp",
      "env": {
        "CONDUCTOR_AGENT_TOKEN": "cdtr_..."
      }
    }
  }
}

Cursor (~/.cursor/mcp.json):

{
  "mcpServers": {
    "conductor": {
      "command": "conductor-mcp",
      "env": {
        "CONDUCTOR_AGENT_TOKEN": "cdtr_..."
      }
    }
  }
}

After restart, the agent's tool list includes 21 conductor_* tools — conductor_project_list, conductor_transition, conductor_export, conductor_verify, plus local-board tools such as conductor_local_list and conductor_local_signal. Tool-execution failures surface as isError: true in the MCP response (per spec); protocol/transport failures use the JSON-RPC error channel.

Custom API endpoint

If you're targeting an environment other than the default (https://airec-api-dxol6hwotq-uk.a.run.app):

export CONDUCTOR_API_BASE=https://your-conductor-api.example.com
# OR pass per-invocation:
conductor --api-base https://your-conductor-api.example.com whoami

Offline pack verification

conductor verify <pack.tar.gz> works without API access. It extracts the archive in a temp dir, walks SHA256SUMS to verify every file's hash, then walks audit-chain/chain.jsonl to confirm per-tenant chain integrity (monotonic chain_position + prev_event_hash threading). If SHA256SUMS.sig is present, it also checks the Ed25519 signature over the exact SHA256SUMS bytes when the optional cryptography backend is available. Invalid, broken, and unavailable signature checks produce a non-clean aggregate and a specific state; they never pass from presence.

The state contract mirrors the embedded audit-chain/verify.py script that ships inside every pack — conductor verify is the more convenient hand-typed form and additionally refuses to summarize unverified-no-lib as clean.

Trust anchor (who signed it)

trustflash_public_key.pem ships inside the pack. A signature that checks out against a key read from the artifact under examination proves only that the pack is internally self-consistent: anyone who edits a pack can regenerate SHA256SUMS, mint a fresh Ed25519 keypair, sign with it, and drop the new public key in. The seal becomes an attribution only when the key is anchored somewhere the pack cannot reach.

Pin the fingerprint(s) you trust — SHA-256 of the key's DER/SPKI bytes, hex, comma/whitespace-separated, sha256: prefix optional:

export FLIGHTDECK_RELEASE_PACK_KEY_FINGERPRINTS=sha256:9f86d081...
conductor verify release.tar.gz

The same env var is read by FlightDeck Desktop's verifier (electron/releasePack.ts), so a key you trust in one is trusted in both. A list is supported so a signer rotation has an overlap window.

Situation State Aggregate
key fingerprint matches an anchor, signature valid verified pass
key fingerprint matches no configured anchor untrusted-key fail
no anchor configured at all unverified-no-anchor fail (incomplete)

No anchor configured is deliberately not a pass. A stock install ships with no compiled-in anchor — the production signer's fingerprint has not been published into this repo, and inventing one to make the check look finished would be the fabrication this whole state family exists to prevent. Until you pin a fingerprint, conductor verify tells you the seal is self-consistent and unattributed, and exits non-zero. That is the honest reading, and it is distinct from untrusted-key, which means the check ran and the key was rejected.

The fingerprint of the key a pack actually carries is printed in the signature_errors line for both states, so pinning is a copy-paste once you have confirmed the key out of band.

Privacy Policy

Full policy: https://ai-flightdeck.com/privacy — Northgate Strategic LLC, effective 2026-08-10.

FlightDeck is local-first. The short version is the whole design:

  • Local board tools send nothing, anywhere. Board reads, packet creation, signals, handoffs, workspace verification and HOLD records operate entirely on the board folder you choose at install. There is no telemetry, no analytics, no crash reporting, no phone-home. No identifier of you or your machine is collected.
  • Cloud tools are opt-in and inert by default. The conductor-cloud tools appear only if you select the all tool set, and do nothing at all until you supply an enrollment token issued to you. Once enabled, each transmits exactly the data its description names — task packets, workflow events, evidence references — over HTTPS to your own tenant.
  • Your data is yours. We do not sell or share it, and do not use it to train any model. Local data lives on your disk; delete it and it is gone. Tenant data leaves live systems within 30 days of deletion.
  • Subprocessors: Cloudflare (site delivery) and Google Cloud (Conductor API hosting). Nothing else.

Which tools touch the network is not something you have to take on faith — it is declared in each tool's annotations, and the board-scoped tools are marked accordingly.

Access, export, deletion, or questions: contact details are on the policy page; we respond within 30 days.

Source

Part of NorthGate AI FlightDeck (flightdeck-connect). See ai-flightdeck.com for documentation.

License and patents

Proprietary — free to install and run as distributed; see LICENSE. The governed-engineering architecture is U.S. patent pending (incl. App. No. 19/765,031).

Metadata

Release files for flightdeck-connect 0.5.5

For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.

Source distribution (sdist)

Source distribution for flightdeck-connect 0.5.5
File Size Uploaded
flightdeck_connect-0.5.5.tar.gz 464.5 kB Details

Built distribution (wheel)

Table of built distributions (wheels) for flightdeck-connect 0.5.5
File Interpreter ABI Platform
flightdeck_connect-0.5.5-py3-none-any.whl Python 3 none any Details

Total release size: 774.1 kB

Release files / flightdeck_connect-0.5.5.tar.gz

Download URL flightdeck_connect-0.5.5.tar.gz
Size 464.5 kB
Tags Source
SHA-256 checksum
How to use checksums
d281a90fa8053fa4dcd84f5f3f07cb81c1d3da9ca315197c1e37289faac7923a
BLAKE2b-256 checksum
How to use checksums
e29a17206654f1815db611c2e7cef0e8a683d2d26580af013c885017d9c0c79e
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 2, 2026.

Transparency log

Release files / flightdeck_connect-0.5.5-py3-none-any.whl

Download URL flightdeck_connect-0.5.5-py3-none-any.whl
Size 309.6 kB
Tags Python 3
SHA-256 checksum
How to use checksums
427e80fac74cf10a53ca94b90a273dc9d30bef6ccfb20ec4b39c219a716d4213
BLAKE2b-256 checksum
How to use checksums
b1c1b6750b16d38260964c710c4157e25e68e8552111ddbb0a82041ca237c557
Upload date
Uploaded using Trusted Publishing?
What is trusted publishing?
Yes
Uploaded via twine/7.0.0 CPython/3.13.14

Provenance

Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.

PyPI Publish Attestation

PyPI verified that this artifact, at this checksum, originated from the publisher listed below.

Signed by GitHub Actions, verified by PyPI on Sep 2, 2026.

Transparency log

Release history Release notifications | RSS feed

0.5.12

2 release files

0.5.11

2 release files

0.5.10

2 release files

0.5.9

2 release files

0.5.8

2 release files

0.5.7

2 release files

0.5.6

2 release files

This release

0.5.5 This release

2 release files

0.5.4

2 release files

0.5.3

2 release files

0.5.2

2 release files

0.5.1

2 release files

0.5.0

2 release files

0.4.0

1 release file

0.3.1

2 release files

0.3.0

2 release files

0.2.0

2 release files

0.1.1

2 release files

0.1.0

2 release files

Anthropic, PBC Visionary sponsor Bloomberg Visionary sponsor Hudson River Trading Visionary sponsor Meta Visionary sponsor NVIDIA Visionary sponsor Microsoft Sustainability sponsor Depot Continuous Integration AWS Cloud computing and Security Sponsor Datadog Monitoring Fastly CDN Google Download Analytics Sentry Error logging StatusPage Status page