See what your coding agent actually sends — and pay less for it.
Works with Claude Code, OpenCode and IBM Bob, and with any agent that can use an HTTPS proxy.
Cortex sits in your agent's request path on your own machine, decrypts the traffic,
and shows you every model call, tool call and agent-to-agent message as it happens.
Think top, for your coding agent: agentop observe shows which sessions are
eating your tokens, your context window and your money, live. Cortex can also strip
the tool definitions your agent never calls, 4–20% of the prompt on every turn.
One binary, no Kubernetes. macOS or Linux, amd64 or arm64.
# 1. Install. Setup lists every change it will make, and asks once.
curl -fsSL https://raw.githubusercontent.com/rossoctl/cortex/main/scripts/install.sh | sh
# 2. In a new terminal, connect your agent, once. The table below has each command.
agentop configure claude-code enable # or opencode, bob, bobshell
# 3. Run your agent the way you always do. No flags, no environment variables.
claude # or opencode, bob
# 4. In another terminal, watch its traffic live.
agentop observeThat's all. From now on every session of that agent goes through Cortex, and nothing
changes about how you start it. An agent that was already running picks up the change
when it restarts. If anything looks wrong, agentop doctor checks the install and
names the command that fixes it.
| Agent | Connect it | |
|---|---|---|
| Claude Code | agentop configure claude-code enable |
Guide |
| OpenCode | agentop configure opencode enable |
Guide |
| IBM Bob | agentop configure bob enable |
Guide |
| Bob Shell | agentop configure bobshell enable |
Guide |
| Any other agent | agentop exec -- <command> |
Guide |
Each configure command is a one-time setup: it asks before it writes, and afterwards
you start the agent exactly as before. status and disable check and undo it. An
agent without a configure command runs under agentop exec, or can be pointed at
the proxy on localhost:47600 with ~/.cortex/ca/ca.crt trusted. Traffic in the Anthropic Messages or OpenAI Chat
Completions format is parsed into model calls and tokens whichever agent sends it, and
priced wherever Cortex has a rate.
- Local only. The proxy listens on loopback, and it only contacts the servers that the programs using it ask for.
- Your own CA. Created on your machine, with its key in
~/.cortex/ca, readable only by you. Cortex never adds it to a keychain itself. - Real certificates are still checked. When a server's certificate fails, Cortex leaves that connection encrypted end to end.
- Read-only, unless you turn on tool pruning.
- History on disk. Sessions, prompts and replies included, are kept in
~/.cortex/sessions, and cost totals in~/.cortex/cost.
agentop uninstall # --purge also deletes ~/.cortexIt asks once, takes Cortex out of every agent it routed, and removes the service and binaries. Remove it has the details.
- Running Cortex — the service, how sessions are grouped, troubleshooting
- agentop — every pane, key and command
- Pricing — rates, gateway discounts, unpriced traffic
- Full install guide —
prerequisites and a walkthrough. Ending the install command in
sh -s -- --helplists the installer's options.
The same binary runs as a Kubernetes sidecar, with what agentic workloads need in production: a verifiable identity per workload and the right credentials for each downstream call (AuthBridge), guardrails that block actions straying from the user's intent, egress control, and spend caps. Start with Running Cortex in Kubernetes; the plugin catalog and architecture reference cover the rest.
Cortex on a laptop is new, so tell us when it breaks: use the Laptop feedback form under new issue, or Slack. A half-finished install with the error pasted in is more useful than a polished bug report you never sent. To work on Cortex, see CONTRIBUTING.md; to report a vulnerability, SECURITY.md.