Skip to main content
Install the local CLI with npm install -g failproofai. Run it with no arguments to open the local policy dashboard. The package requires Node.js 20.9 or newer. Bun 1.3 or newer is supported for development and source installs. failproofai configure and failproofai setup are aliases for failproofai config. failproofai policy, failproofai pack and failproofai p are all spellings of failproofai policies — packs and single policies were three commands for one idea and are now one. The older spellings still work, with two exceptions: pack list <source> is now policies show <source>, and pack build is now publish.

Set up a machine

Install the CLI, then read the machine key into the shell. read -s takes it at a prompt that does not echo, so it never appears in a command:
Then set the machine up and choose what it enforces:
failproofai config is the whole of setup: it installs the failproofaid service (root once, via sudo -n — never an interactive password prompt), wires hooks into every agent CLI it finds, and connects to Cloud when a key is available. With no terminal — CI, a container, an agent driving it — it applies rather than asking, and exits 1 if anything it was asked to do did not happen. It chooses no policies. That is the second command’s job, and without it a freshly configured machine enforces nothing but the always-on guard. Prefer the environment variable over --token: a command-line argument is readable from ps by every user on the box. That is all the variable protects against — a key typed into any command, export included, still lands in shell history, which is why it is read in with read -s above. In CI, set it from the secret store and keep shell tracing (set -x) off, or the trace prints it.
--connect <url> enrols a machine that is already set up. It returns as soon as enrolment succeeds — it does not install the daemon and does not wire any hooks. Use plain failproofai config (or failproofai config --token <key>) on a machine that has not been set up yet, or it will read as connected while collecting and enforcing nothing.
Run failproofai without arguments to open the local policy dashboard.

Configuration flags

Local pauses suspend builtin, custom, convention, and pack policies for one session. They always expire and do not disable Cloud-managed policies. block-failproofai-commands — which is always on and cannot itself be disabled or paused — prevents an instrumented agent from using this escape hatch itself.

Policy flags

Delivery and maintenance flags

failproofai update should be run after npm install -g failproofai@latest; it performs home-layout migrations, installs the matching daemon binary, and restarts the service. It then moves every Hermes profile that already uses FailproofAI to the linked native plugin and prints one line per profile. --no-daemon skips the daemon step. update exits non-zero when the daemon could not be replaced, a migration failed, or a Hermes profile could not be migrated (for example because the running daemon cannot serve the native plugin, in which case its shell hooks are left in place).

Harness paths

Supported harness names are claude, codex, copilot, cursor, opencode, pi, hermes, openclaw, factory, devin, antigravity, and goose. Labels namespace derived agent IDs when two roots contain copies of the same project. Overlapping roots and duplicate labels are rejected to prevent duplicate collection or cursor corruption. Extra-path configuration reloads without a daemon restart. Container environments can replace file-configured extra paths with a comma-separated variable named FAILPROOFAI_<HARNESS>_EXTRA_PATHS, for example:

Environment variables

Use configuration files for persistent machine behavior. Environment variables are most useful for containers, tests, and one process. Agent-specific home variables such as CLAUDE_PROJECTS_PATH, CURSOR_HOME, HERMES_HOME, and OPENCLAW_HOME override where Failproof AI discovers local sessions for that harness.

Pause or remove a machine safely

A local session pause does not disable Cloud-managed policies. Restore Cloud deployments through the Cloud enforcement workflow when the rollout itself is the problem. Before removing the npm package, remove installed hooks and the daemon:
Run failproofai <command> --help for version-specific details.
Run failproofai uninstall before npm rm -g failproofai; npm does not remove installed agent hooks or the daemon service.