gh pr create, git push, railway up, kubectl delete. The Passport hook puts that work in the same audit log as everything else your agents do.
It only watches. It never blocks a command, never answers a permission question, and never delays your agent.
Turn it on
--apply you see exactly what would change and nothing is written. The command adds one PostToolUse entry to ~/.claude/settings.json and leaves your other hooks alone.
Check what is registered:
What it records
After each shell command, the hook reads the command on your own machine and sends Passport only:- the tool that ran, such as
ghorterraform - a coarse verb, such as
pr createorapply - an action class: read, write, destructive, api, sql, http, or unknown
- whether the command succeeded, how long it took, and the name of the folder you were in
- your agent’s session identifier, so a run hangs together
gh CLI, git CLI, and so on.
What it never records
The hook never sends, and Passport never stores:- the command line or any of its arguments
- the command’s output
- your full folder path, only the last folder name
- anything from your environment, including tokens
make target, an alias. Passport records those as opaque and says which shape it was, never what they contained.
Turn it off
PASSPORT_HOOK_DISABLED=1.
Codex registration is not automated yet. Add a PostToolUse hook that runs passport hook and Passport records it the same way.
See also Activity and audit.