Skip to main content

Official Sernixa CLI for policy-governed local AI agent actions

Project description

Sernixa CLI

The official terminal and local-agent integration for Sernixa governance. The CLI evaluates actions against the real Sernixa control plane, installs supported agent hooks and MCP configuration, launches safe local discovery, and exposes operational evidence without a dashboard-only workflow.

Install and set up

macOS and Linux:

python3 -m pip install --upgrade sernixa-cli
sernixa auth login
sernixa protect
sernixa protect --status

Windows PowerShell:

py -m pip install --upgrade sernixa-cli
sernixa auth login
sernixa protect
sernixa protect --status

sernixa auth login opens the Sernixa sign-in page, displays a short confirmation code, and stores a revocable CLI session after approval. The session inherits the signed-in user's organization, role, plan, and feature entitlements. Check the active identity without exposing its credential:

sernixa auth status

Organization API keys remain available for CI and other non-interactive automation. Send the key over stdin so it is not saved in command history:

Get-Clipboard | sernixa auth login --api-key-stdin

The key is never passed as a command-line argument or printed.

Then run sernixa by itself to open the persistent governance console. Type @ to open the selectable command palette, use the arrow keys, and press Enter:

sernixa › @status
sernixa › @discover
sernixa › @protect
sernixa › @integrations
sernixa › @events
sernixa › @approvals
sernixa › @exit

The console is project-aware, remains open across commands, supports tab completion and private local history, and dispatches only Sernixa commands. The palette shows only actions available on the authenticated plan; direct commands are still checked by the backend. @ is the primary command-palette prefix and slash-prefixed forms remain compatible. Every normal command such as validate request.json also works inside it. Bare sernixa remains concise when stdout or stdin is not a terminal, so scripts and CI never hang; sernixa shell is the explicit interactive entry point.

sernixa protect is the recommended first run. It detects installed Codex, Claude, and Cursor hosts, validates live organization policy access, installs Sernixa as a first-class Codex and Claude Code plugin, configures the supported Cursor boundary, and prints the actual coverage limitations instead of claiming control over host events that were never emitted:

sernixa protect
sernixa protect --status
sernixa protect --target codex --target claude
sernixa protect --dry-run --json

After installation, restart open agent hosts. In Codex, open /plugins; in Claude Code, open /plugin. Select Sernixa Security and trust its hook and MCP server when prompted. Once each plugin is visible, Sernixa removes only its own older standalone hook/MCP blocks (with backups), so the same enforcement command is not registered twice. The plugin still contains a hook because pre-tool blocking requires one; it is owned and displayed as part of the plugin rather than user config. sernixa setup remains available for the broader developer setup, including Claude Desktop and the bounded sernixa:// dashboard launcher. It preserves unrelated entries, backs up changed files, and reports host restart or hook-trust steps. Preview it without changing files:

sernixa setup --dry-run
sernixa setup --target codex --target cursor --json

For local repository development:

python3 -m venv .venv-cli
source .venv-cli/bin/activate
pip install -e packages/sernixa -e packages/sernixa-agent -e apps/cli

The CLI defaults to https://api.sernixa.com. Stored credentials use the platform user-config directory and mode 0600 on Unix. SERNIXA_ACCESS_TOKEN, SERNIXA_API_KEY, and SERNIXA_BASE_URL override the stored configuration for non-interactive use.

One-command Auto Discover

sernixa discover
sernixa discover --json
sernixa discover --job discjob_0123456789abcdef0123456789abcdef

The command validates auth, initializes the supported local agent when needed, passes the stored credential only through the one-shot child-process environment, enrolls the stable machine ID, creates or accepts a policy-scoped job for that machine, runs one sync/task cycle, and waits for the terminal job result. The credential is not printed or duplicated into a second token file.

The Command Center opens the same flow through sernixa://discover after a direct user click and an OS/browser confirmation. The native URL accepts only the fixed discovery action and an optional validated job ID; it cannot carry commands, credentials, paths, or environment values. If the launcher is unavailable, the dashboard shows the exact fallback command.

Discovery candidates are observations for review. Enrollment is inventory. An accepted agent sync is proof. No discovery result silently becomes a managed MCP server.

Codex, Claude, and Cursor

Supported global targets:

  • claude: a visible Sernixa Security plugin containing enforcement/lifecycle hooks, the Sernixa MCP server, and a protection skill. Users can inspect it from /plugin.
  • claude-desktop: real stdio MCP server in the OS-specific Claude Desktop configuration.
  • codex: a visible Sernixa Security plugin containing the enforcement hook, Sernixa MCP server, and protection skill. Users review/trust the plugin hook, and can inspect it from /plugins.
  • cursor: global MCP entry in ~/.cursor/mcp.json, shared by Cursor IDE and CLI.

sernixa protect is the supported automatic installer. Anyone can also add the public repository marketplace directly:

codex plugin marketplace add abhishekdhull63/Sernixa.ai-Web
codex plugin add sernixa@sernixa

claude plugin marketplace add abhishekdhull63/Sernixa.ai-Web
claude plugin install sernixa@sernixa --scope user

Inside Claude Code, the equivalent interactive commands are /plugin marketplace add abhishekdhull63/Sernixa.ai-Web, /plugin install sernixa@sernixa, and /reload-plugins.

The legacy config installer remains available for Claude Desktop, Cursor, and older host builds:

sernixa hook install claude
sernixa hook install claude-desktop
sernixa hook install codex
sernixa hook install cursor

sernixa hook repair cursor
sernixa hook status

Claude Code and Codex hooks call sernixa hook run <provider> before tool execution and record privacy-bounded session, tool, subagent, and compaction lifecycle evidence. allow continues through normal host permissions and deny blocks. Claude Code maps review to its supported human prompt. Current Codex PreToolUse does not support an ask result, so Sernixa maps review to a fail-closed deny with an explicit human-review reason instead of returning a hook shape that Codex would ignore. A policy-evaluation API or configuration failure exits with code 2, which both hosts treat as blocking; there is no local allow fallback. Observational lifecycle delivery is silent and non-blocking because a telemetry outage after an action cannot safely reverse that action.

Hook handlers allow 35 seconds for the live policy request; the CLI request budget is 30 seconds. This prevents slow semantic evaluations from being killed by a shorter host-hook timeout.

Claude Code, Claude Desktop, Codex, and Cursor run sernixa mcp serve. The stdio MCP server exposes four non-mutating tools:

  • sernixa_policy_check: evaluate one proposed action.
  • sernixa_plan_check: evaluate a declared multi-step plan.
  • sernixa_execution_passport: issue and persist a signed, exact-step Execution Passport for an allowed plan.
  • sernixa_identity: validate auth and return non-secret principal metadata.

MCP tools provide explicit model capabilities; the installed hooks are the local tool-call enforcement points.

Execution Passports

An approved plan is not a reusable local “allow.” Sernixa signs each exact tool/action/arguments/resource binding, and the API atomically consumes the matching proof once before execution. Changed arguments, undeclared tools, expired tokens, and replayed steps fail closed.

Issue or inspect a passport directly:

sernixa passport issue --agent-type codex plan.json
sernixa passport status
sernixa passport clear

In Codex, Claude, Cursor, or another MCP host, ask the model to call sernixa_execution_passport with its complete intended plan before it begins tool use. The installed Codex/Claude pre-tool hook then consumes the matching proof for each emitted tool event. The passport authorizes only the declared steps; it never executes them and never bypasses native host permissions.

Coverage remains explicit: no integration can block a capability that the host does not expose through a hook or MCP call. On current Codex Windows builds, Sernixa remains available as a plugin and MCP policy/passport layer, while pre-tool blocking depends on Codex adding Windows hook support.

Governance and execution

sernixa validate payload.json
cat payload.json | sernixa validate --json
sernixa validate --from-claude < claude-hook.json
sernixa validate --from-codex < codex-hook.jsonl
sernixa validate-plan --agent-type codex plan.json
sernixa validate-many --output json policies/*.json
sernixa exec --plan plan.json -- npm test
sernixa codex-exec --plan codex-plan.json -- codex exec "fix lint"

Exit codes are stable:

  • 0: success or policy allow
  • 1: deny, review required, invalid evidence, or non-success terminal result
  • 2: configuration, parsing, auth, network, or API failure

Human output is intentionally concise. Use --json only when a script needs structured details; JSON decisions omit the duplicated raw backend payload.

validate-plan calls the canonical plan endpoint. exec and codex-exec run the child command only after every planned step is allowed and bound to its proof.

Audit, approvals, and Flight Recorder

sernixa events --limit 25
sernixa events --type governance_agent_plan_evaluated --json

sernixa approvals list
sernixa approvals decide approval_123 approved --reason "Reviewed bounded deployment."
sernixa approvals decide approval_456 rejected --reason "Production scope is too broad."

sernixa flight verify
sernixa flight verify --stream stream_123 --json
sernixa flight collectors

These commands call the authenticated organization endpoints and inherit backend permissions and feature entitlements. sernixa decisions remains a backward-compatible alias for the pending approval queue. Replay is not claimed because the backend does not expose an authorized decision-replay endpoint.

Stable configuration overrides

  • SERNIXA_CONFIG_FILE
  • SERNIXA_ACCESS_TOKEN
  • SERNIXA_CLI_TIMEOUT_SECONDS
  • SERNIXA_PLAN_SESSION_FILE
  • SERNIXA_HISTORY_FILE
  • SERNIXA_CLAUDE_CONFIG_FILE
  • SERNIXA_CLAUDE_DESKTOP_CONFIG_FILE
  • SERNIXA_CODEX_HOOKS_FILE
  • SERNIXA_CODEX_CONFIG_FILE
  • SERNIXA_CURSOR_CONFIG_FILE

Project-scoped Codex files are intentionally not modified by global setup. Invalid JSON or TOML fails closed with the exact path and a repair command. Existing files are backed up before material changes.

Project details


Download files

Download the file for your platform. If you're not sure which to choose, learn more about installing packages.

Source Distribution

sernixa_cli-0.4.4.tar.gz (79.1 kB view details)

Uploaded Source

Built Distribution

If you're not sure about the file name format, learn more about wheel file names.

sernixa_cli-0.4.4-py3-none-any.whl (64.1 kB view details)

Uploaded Python 3

File details

Details for the file sernixa_cli-0.4.4.tar.gz.

File metadata

  • Download URL: sernixa_cli-0.4.4.tar.gz
  • Upload date:
  • Size: 79.1 kB
  • Tags: Source
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for sernixa_cli-0.4.4.tar.gz
Algorithm Hash digest
SHA256 6cc823d6cb64c5bfed3b66299d4c18fac8de8b0fa98901021d90e1d312089c03
MD5 b343f239a2cdbef508a1fdbb0b39422b
BLAKE2b-256 517a1ae0cb4e3bfc501b7e1f220ec42424b0786bd07dc1df5b1020fd0d694f6b

See more details on using hashes here.

Provenance

The following attestation bundles were made for sernixa_cli-0.4.4.tar.gz:

Publisher: release-sernixa-cli.yml on abhishekdhull63/Sernixa.ai-Web

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

File details

Details for the file sernixa_cli-0.4.4-py3-none-any.whl.

File metadata

  • Download URL: sernixa_cli-0.4.4-py3-none-any.whl
  • Upload date:
  • Size: 64.1 kB
  • Tags: Python 3
  • Uploaded using Trusted Publishing? Yes
  • Uploaded via: twine/6.1.0 CPython/3.13.14

File hashes

Hashes for sernixa_cli-0.4.4-py3-none-any.whl
Algorithm Hash digest
SHA256 9fd64dee63b694de9cfdd51b5b80fe555a4505c3870caed53a9a3f7e4381fbbc
MD5 7b20bd319ec194fd7a54aafdbc5fe5cc
BLAKE2b-256 bdf9ffe351ffd68d0df32fbd317ab5d3ba5e4da659a2d34d4b4a5adbf350c98c

See more details on using hashes here.

Provenance

The following attestation bundles were made for sernixa_cli-0.4.4-py3-none-any.whl:

Publisher: release-sernixa-cli.yml on abhishekdhull63/Sernixa.ai-Web

Attestations: Values shown here reflect the state when the release was signed and may no longer be current.

Supported by

AWS Cloud computing and Security Sponsor Datadog Monitoring Depot Continuous Integration Fastly CDN Google Download Analytics Pingdom Monitoring Sentry Error logging StatusPage Status page