HookBus spec v1.0 draft · implements AgentHook v0.2 draft HookBus is one implementation. AgentHook is the open runtime-evidence standard underneath it.
Read the spec →

HookBus®

The open agent event bus.
HookBus is the deployable infrastructure. AgentHook is the portable evidence standard underneath it.

HookBus captures what AI agents do, as they do it, and routes each event to independent subscribers outside the agent.

Subscribers can record, audit, track cost, or return an allow, deny or ask decision.

Start with HookBus Light and AgentProtect CRE Light. Claude Code, Codex CLI, Amp, OpenCode, Hermes Agent, OpenClaw, and any hook-aware runtime can publish to the same bus.

Deploy HookBus today. Keep the evidence portable with AgentHook.
curl -fsSL https://hookbus.com/install.sh | bash
Installs HookBus Light plus AgentProtect CRE Light. Docker. Apache 2.0. Self-host in 60 seconds.
HookBus Light Apache 2.0 HookBus spec v1.0 Publisher shims available

When an agent goes wrong, can you tell what it did?

HookBus sits outside the agent. Every lifecycle event passes through it in one format, to whatever records or reviews it: an audit log, a cost tracker, a policy check, or a subscriber you write yourself.

HookBus is the capture layer. It is the open-source instrument Agentic Thinking uses in its research on AI agent incidents.

HookBus routes events. AgentHook makes those events portable.

A PreToolUse, PostToolUse, approval decision, denial reason, runtime attestation, and action-governance profile should mean the same thing whether the collector is HookBus, a SIEM, an OpenTelemetry pipeline, or an internal governance service.

HookBus proves AgentHook in practice. AgentHook keeps HookBus from becoming a closed island.

Publishers emit. The bus routes. Subscribers react.

Every AI agent action is a lifecycle event. HookBus captures them all and fans them out to subscribers in parallel. Sync subscribers return a verdict (allow, deny, ask) and a reason. The bus consolidates on deny-wins. The reason is injected back into the agent’s next turn. Async subscribers observe without blocking.

Publishers
OpenClaw
Extension
Live
Hermes Agent
Plugin
Live
Claude Code
Hook
Live
Amp Code
Plugin
Live
Codex CLI
Hook
Live
OpenCode
Plugin
Live
Any HTTP Client
Webhook
Live

HOOKBUS®

Agent Event Bus
Event Routing Fan-out Forwards verdicts Hot Reload Health Checks
Subscribers
AgentProtect CRE Light
Sync · Light · MIT
Live · Free
AgentSpend
Async · Light · MIT
Live · Free
Build your own →
Any language. Any protocol.
Sync (blocks until decision) Async (fire and forget) Live · free & open-source

60 seconds to your first recorded agent event.

  1. Install

    One command. Pulls the Apache 2.0 bus and AgentProtect CRE Light as Docker images. Generates a bearer token. AgentSpend is optional.

    curl -fsSL https://hookbus.com/install.sh | bash
  2. Publish a test event

    Any tool that can POST JSON can publish. No SDK required.

    source ~/hookbus-light/.env
    curl -X POST http://localhost:18800/event \
      -H "Authorization: Bearer $HOOKBUS_TOKEN" \
      -H "Content-Type: application/json" \
      -d '{
        "event_id": "manual-smoke-1",
        "event_type": "PreToolUse",
        "timestamp": "2026-04-28T00:00:00Z",
        "source": "manual",
        "session_id": "hello",
        "tool_name": "Bash",
        "tool_input": {"command": "rm -rf /"},
        "metadata": {}
      }'
  3. Watch the verdict

    AgentProtect CRE Light evaluates, returns decision: deny with a reason. The bus consolidates and threads it back to the caller. Open http://localhost:18800/ to see the event in the dashboard.

  4. Wire up a real agent

    Pick a publisher shim for your runtime. Claude Code, Amp, Hermes, OpenClaw, Codex, or any SDK with lifecycle hooks.

    See publisher shims ↓

Any agent with lifecycle hooks speaks HookBus.

A publisher shim normalises the agent’s raw hook format into the canonical HookBus envelope and posts it to the bus. Six runtimes have open-source publishers today.

Every publisher is open source on GitHub under Apache 2.0 or MIT. Install with one curl command, fork and audit the source, or contribute back. All repos live under github.com/agentic-thinking.

Claude Code Live

Anthropic’s agentic CLI. Four hook events wired: UserPromptSubmit, PreToolUse, PostToolUse, Stop. MIT.

curl -fsSL https://hookbus.com/publishers/claude-code | bash

Amp Code Live

TypeScript plugin using Amp’s native plugin API. All five lifecycle events (session.start, agent.start, tool.call, tool.result, agent.end). MIT.

curl -fsSL https://hookbus.com/publishers/amp | bash

Hermes Agent Live

Python plugin for Hermes Agent. Hooks pre/post tool calls and post API requests. Exact token usage attribution. MIT.

curl -fsSL https://hookbus.com/publishers/hermes | bash

OpenClaw Live

Node plugin for OpenClaw’s extension API. Before/after tool call, LLM output. Model and token usage auto-attributed. MIT.

curl -fsSL https://hookbus.com/publishers/openclaw | bash

Codex CLI (OpenAI) Live

Codex CLI publisher for HookBus. SessionStart, UserPromptSubmit, PreToolUse, PostToolUse, and Stop mapped to AgentHook events. Includes install doctor and central-bus identity metadata.

curl -fsSL https://hookbus.com/publishers/codex | bash

OpenCode Live

Native OpenCode plugin plus wrapper. Prompt, model-call, tool and session events mapped to AgentHook. Install from the repository with ./install.sh.

Other runtimes Contributions welcome

Gemini CLI, Cursor, GitHub Copilot CLI, Devin CLI and the OpenAI Agents SDK all expose hooks a publisher could use. None has a HookBus publisher yet. See the runtime audit for what each one exposes.

Add your runtime → · Any SDK with lifecycle hooks can publish. The spec shows what the envelope must contain.

Two open subscribers today. Build your own.

A subscriber receives events, returns a verdict with a reason and metadata, publishes context back onto the bus. Sync blocks. Async observes. Any language that can serve JSON.

A subscriber tuned to fintech rules. A DLP filter for healthcare PII schemas. A cost tracker that posts to Jira. A memory layer backed by your vector database. Examples, not limits.

AgentProtect CRE Light Free Governance

by Agentic Thinking

Ships with HookBus Light. L1 deterministic policy rules. Allow / deny / ask on PreToolUse. MIT licensed.

docker run agenticthinking/cre-agentprotect

AgentSpend Free Cost

by Agentic Thinking

Ships with HookBus Light. Token and cost tracking per session, per agent, per team. SQLite store, dashboard on :8883.

docker run agenticthinking/agentspend

An open specification. A reference implementation. Anyone can build on it.

The bus you install is the reference implementation, Apache 2.0. The envelope format, the subscriber contract, and the consolidation rules are defined in a versioned spec. Independent implementations in Go, Rust, Node, anything are welcome and expected.

The AgentHook specification is published and stewarded by Agentic Thinking Ltd under a perpetual Apache 2.0 commitment, with stewardship transfer to a neutral foundation on documented triggers. Read the charter →

Spec
HookBus spec v1.0 draft · implements AgentHook v0.2
Dated
2026-04-08
Licence
Apache 2.0

The spec defines: publisher envelope schema, subscriber response schema (decision + reason + metadata), transport options (unix socket, HTTP, in-process), event-type normalisation map across popular SDKs, and the deny-wins consolidation rule.

Implement AgentHook without HookBus

HookBus is the reference implementation, not the only valid implementation. Build your own publisher, subscriber, collector, bus, or OpenTelemetry exporter against AgentHook.

Build where you see a need.

HookBus is an open platform. The protocol is Apache 2.0 forever. Subscribers can be open or closed, free or paid, ours or yours. Where HookBus goes next is where you take it.