Skip to content

Repository files navigation

Cortex

See what your coding agent actually sends — and pay less for it.

A terminal installs Cortex with one command and points Claude Code at it. Three Claude Code sessions run in separate directories, and agentop then lists all three with their token counts, cost and remaining context. Pressing $ breaks the spend down by tier, where cache reads dominate. Drilling into the busiest session shows the whole conversation and the fifteen-tool manifest it re-sends on every turn.

Cortex sits in your agent's request path, decrypts its traffic, and shows you the model calls, tool calls and agent-to-agent messages as they happen. It can also strip the tool definitions your agent never calls, which is 4–20% of the prompt on every turn.

Think top, for your coding agent. Where top shows which processes are eating your CPU, agentop observe shows which agent sessions are eating your tokens, your context window and your money — live, as they run.

One binary, no Kubernetes. macOS or Linux, amd64 or arm64.

Quick start

curl -fsSL https://raw.githubusercontent.com/rossoctl/cortex/main/scripts/install.sh \
  | sh -s -- --claude-code

The script downloads the release, verifies its checksums, and hands off to agentop setup. Setup lists every change it will make — the binaries, your PATH, the config, the service, Claude Code's settings — and asks once. It ticks off each step as it finishes, and undoes them all if one fails. Cortex then runs as a background service that survives crashes and logins.

Then open two new terminals:

agentop observe # the viewer
claude          # as usual — no environment variables to set

Your agent's calls stream into agentop. Cortex only reads them; nothing is rewritten.

  • Cut token cost — one more command
  • Start, stop, remove — agentop service status | start | stop
  • Something wrong? agentop doctor checks the install, changes nothing, and names the command that fixes each problem it finds
  • Run it in Kubernetes — sidecars, Keycloak, SPIFFE/SPIRE

Any agent works, not only Claude Code (OpenCode has its own agentop configure command): point it at localhost:47600 and trust ~/.cortex/ca/ca.crt.

curl | sh never executes unreleased code — the script re-runs the copy from the newest release. Pin or override with --ref (CONTRIBUTING.md). Add --no-modify-path to keep it out of your shell profile.

Full install guide: Cortex on your laptop — prerequisites, step-by-step walkthrough, service management and troubleshooting.

Uninstall

agentop uninstall

agentop uninstall lists what it will remove and asks once. It unroutes Claude Code and OpenCode (and IBM Bob, where Cortex routed it), stops and removes the service, takes out the PATH lines setup added unless other tools in ~/.local/bin still need them, and deletes agentop, cortex and cortex-session-dump from ~/.local/bin. A step that fails is reported with its fix, and the rest still run.

Claude Code and OpenCode go straight to their APIs again, and Cortex stops and no longer starts at login. Your config, CA and cost history stay in ~/.cortex, so the install command above brings it back as it was (and agentop configure opencode enable for OpenCode). agentop uninstall --purge deletes ~/.cortex as well, unless a removal before it failed: then ~/.cortex stays, and the end lists it as left behind.

Restart any claude that was already running: it still points at Cortex. claude --resume picks the conversation back up. OpenCode needs no restart from you: uninstall restarts its background service when it finds it running.

To delete everything and check nothing is left, see Remove it. If agentop itself is gone, remove it by hand.

Feedback

Note

Cortex on a laptop is new, and we want to hear when it breaks.

If the install failed, the numbers looked wrong, or anything was unclear:

A half-finished install with the error pasted in is more useful to us than a polished bug report you never sent.

What else Cortex does

Traffic visibility is the part you can use in a minute. The same binary provides the platform services agentic workloads need in production, as a sidecar or standalone:

  • Identity & access — a verifiable identity per workload, and the right credentials for each downstream call, so an agent never holds a tool's secret. This layer is AuthBridge.
  • Guardrails — block agent actions that stray from the user's intent or aren't grounded in the conversation.
  • Egress control — govern which external services a workload can reach.
  • Cost controls — trim the context a workload sends, and cap its spend.

Everything is a plugin in one pipeline; the plugin catalog lists what ships, and the architecture reference explains how a request flows through it. The shared library is core/; the binaries live under cmd/.

License

Apache 2.0

About

Repository for kagenti extensions projects

Resources

Contributing

Security policy

Stars

15 stars

Watchers

3 watching

Forks

Releases

Packages

Used by

Contributors

Languages