HookBus captures what AI agents do, as they do it, and routes each event to independent subscribers outside the agent.
Subscribers can record, audit, track cost, or return an allow, deny or ask decision.
Start with HookBus Light and AgentProtect CRE Light. Claude Code, Codex CLI, Amp, OpenCode, Hermes Agent, OpenClaw, and any hook-aware runtime can publish to the same bus.
curl -fsSL https://hookbus.com/install.sh | bash
HookBus sits outside the agent. Every lifecycle event passes through it in one format, to whatever records or reviews it: an audit log, a cost tracker, a policy check, or a subscriber you write yourself.
A PreToolUse, PostToolUse, approval decision, denial reason, runtime attestation, and action-governance profile should mean the same thing whether the collector is HookBus, a SIEM, an OpenTelemetry pipeline, or an internal governance service.
Every AI agent action is a lifecycle event. HookBus captures them all and fans them out to subscribers in parallel. Sync subscribers return a verdict (allow, deny, ask) and a reason. The bus consolidates on deny-wins. The reason is injected back into the agent’s next turn. Async subscribers observe without blocking.
One command. Pulls the Apache 2.0 bus and AgentProtect CRE Light as Docker images. Generates a bearer token. AgentSpend is optional.
curl -fsSL https://hookbus.com/install.sh | bash
Any tool that can POST JSON can publish. No SDK required.
source ~/hookbus-light/.env
curl -X POST http://localhost:18800/event \
-H "Authorization: Bearer $HOOKBUS_TOKEN" \
-H "Content-Type: application/json" \
-d '{
"event_id": "manual-smoke-1",
"event_type": "PreToolUse",
"timestamp": "2026-04-28T00:00:00Z",
"source": "manual",
"session_id": "hello",
"tool_name": "Bash",
"tool_input": {"command": "rm -rf /"},
"metadata": {}
}'
AgentProtect CRE Light evaluates, returns decision: deny with a reason. The bus consolidates and threads it back to the caller. Open http://localhost:18800/ to see the event in the dashboard.
Pick a publisher shim for your runtime. Claude Code, Amp, Hermes, OpenClaw, Codex, or any SDK with lifecycle hooks.
A publisher shim normalises the agent’s raw hook format into the canonical HookBus envelope and posts it to the bus. Six runtimes have open-source publishers today.
Every publisher is open source on GitHub under Apache 2.0 or MIT. Install with one curl command, fork and audit the source, or contribute back. All repos live under github.com/agentic-thinking.
Anthropic’s agentic CLI. Four hook events wired: UserPromptSubmit, PreToolUse, PostToolUse, Stop. MIT.
TypeScript plugin using Amp’s native plugin API. All five lifecycle events (session.start, agent.start, tool.call, tool.result, agent.end). MIT.
Python plugin for Hermes Agent. Hooks pre/post tool calls and post API requests. Exact token usage attribution. MIT.
Node plugin for OpenClaw’s extension API. Before/after tool call, LLM output. Model and token usage auto-attributed. MIT.
Codex CLI publisher for HookBus. SessionStart, UserPromptSubmit, PreToolUse, PostToolUse, and Stop mapped to AgentHook events. Includes install doctor and central-bus identity metadata.
Native OpenCode plugin plus wrapper. Prompt, model-call, tool and session events mapped to AgentHook. Install from the repository with ./install.sh.
Gemini CLI, Cursor, GitHub Copilot CLI, Devin CLI and the OpenAI Agents SDK all expose hooks a publisher could use. None has a HookBus publisher yet. See the runtime audit for what each one exposes.
Add your runtime → · Any SDK with lifecycle hooks can publish. The spec shows what the envelope must contain.
A subscriber receives events, returns a verdict with a reason and metadata, publishes context back onto the bus. Sync blocks. Async observes. Any language that can serve JSON.
A subscriber tuned to fintech rules. A DLP filter for healthcare PII schemas. A cost tracker that posts to Jira. A memory layer backed by your vector database. Examples, not limits.
Ships with HookBus Light. L1 deterministic policy rules. Allow / deny / ask on PreToolUse. MIT licensed.
HookBus is an open protocol. Any subscriber that implements the response contract runs on any HookBus instance the moment you register it. No approval. No email. No queue.
Read the spec. Write a handler in any language that can serve JSON. Add it to your subscribers.yaml. That is the whole flow.
Want it in the public registry so other developers can find it? Open a PR.
The bus you install is the reference implementation, Apache 2.0. The envelope format, the subscriber contract, and the consolidation rules are defined in a versioned spec. Independent implementations in Go, Rust, Node, anything are welcome and expected.
The AgentHook specification is published and stewarded by Agentic Thinking Ltd under a perpetual Apache 2.0 commitment, with stewardship transfer to a neutral foundation on documented triggers. Read the charter →
The spec defines: publisher envelope schema, subscriber response schema (decision + reason + metadata), transport options (unix socket, HTTP, in-process), event-type normalisation map across popular SDKs, and the deny-wins consolidation rule.
HookBus is the reference implementation, not the only valid implementation. Build your own publisher, subscriber, collector, bus, or OpenTelemetry exporter against AgentHook.
HookBus is an open platform. The protocol is Apache 2.0 forever. Subscribers can be open or closed, free or paid, ours or yours. Where HookBus goes next is where you take it.