[{"data":1,"prerenderedAt":785},["ShallowReactive",2],{"navigation_docs":3,"-project-data-and-privacy":270,"-project-data-and-privacy-surround":780},[4,28,51,110,243],{"title":5,"path":6,"stem":7,"children":8},"Get started","\u002Fget-started","1.get-started",[9,12,16,20,24],{"title":10,"path":6,"stem":11},"Overview","1.get-started\u002Findex",{"title":13,"path":14,"stem":15},"Why Kraft","\u002Fget-started\u002Fwhy-kraft","1.get-started\u002F0.why-kraft",{"title":17,"path":18,"stem":19},"Install","\u002Fget-started\u002Finstall","1.get-started\u002F1.install",{"title":21,"path":22,"stem":23},"Your first work item","\u002Fget-started\u002Ffirst-work-item","1.get-started\u002F2.first-work-item",{"title":25,"path":26,"stem":27},"Troubleshooting and FAQ","\u002Fget-started\u002Ftroubleshooting","1.get-started\u002F3.troubleshooting",{"title":29,"path":30,"stem":31,"children":32},"Concepts","\u002Fconcepts","2.concepts",[33,35,39,43,47],{"title":10,"path":30,"stem":34},"2.concepts\u002Findex",{"title":36,"path":37,"stem":38},"Vocabulary","\u002Fconcepts\u002Fvocabulary","2.concepts\u002F1.vocabulary",{"title":40,"path":41,"stem":42},"How a work item runs","\u002Fconcepts\u002Fhow-a-work-item-runs","2.concepts\u002F2.how-a-work-item-runs",{"title":44,"path":45,"stem":46},"Caps and budgets","\u002Fconcepts\u002Fcaps-and-budgets","2.concepts\u002F3.caps-and-budgets",{"title":48,"path":49,"stem":50},"Why a permission gate","\u002Fconcepts\u002Fpermission-gate","2.concepts\u002F4.permission-gate",{"title":52,"path":53,"stem":54,"children":55},"Guides","\u002Fguides","3.guides",[56,58,62,66,70,74,78,82,86,90,94,98,102,106],{"title":10,"path":53,"stem":57},"3.guides\u002Findex",{"title":59,"path":60,"stem":61},"Use Kraft from your agent","\u002Fguides\u002Fagent-integration","3.guides\u002F01.agent-integration",{"title":63,"path":64,"stem":65},"Kraft Lite","\u002Fguides\u002Fkraft-lite","3.guides\u002F02.kraft-lite",{"title":67,"path":68,"stem":69},"Remote access","\u002Fguides\u002Fremote-access","3.guides\u002F03.remote-access",{"title":71,"path":72,"stem":73},"Add or override a harness","\u002Fguides\u002Fadding-a-harness","3.guides\u002F04.adding-a-harness",{"title":75,"path":76,"stem":77},"Schedule or webhook work","\u002Fguides\u002Fschedule-and-webhook-work","3.guides\u002F05.schedule-and-webhook-work",{"title":79,"path":80,"stem":81},"Add a security review or a gate reviewer","\u002Fguides\u002Fadd-review-agents","3.guides\u002F06.add-review-agents",{"title":83,"path":84,"stem":85},"Kraft for VS Code","\u002Fguides\u002Fvscode","3.guides\u002F07.vscode",{"title":87,"path":88,"stem":89},"Reviewing a change","\u002Fguides\u002Freview-a-change","3.guides\u002F08.review-a-change",{"title":91,"path":92,"stem":93},"Write your own chain","\u002Fguides\u002Fwrite-your-own-chain","3.guides\u002F09.write-your-own-chain",{"title":95,"path":96,"stem":97},"Switch a harness","\u002Fguides\u002Fswitch-harness","3.guides\u002F10.switch-harness",{"title":99,"path":100,"stem":101},"Upgrade your templates","\u002Fguides\u002Fupgrading-templates","3.guides\u002F11.upgrading-templates",{"title":103,"path":104,"stem":105},"Operations","\u002Fguides\u002Foperations","3.guides\u002F12.operations",{"title":107,"path":108,"stem":109},"Worker Kit","\u002Fguides\u002Fworker-kit","3.guides\u002F13.worker-kit",{"title":111,"path":112,"stem":113,"children":114},"Reference","\u002Freference","4.reference",[115,117,139,183,201,205,227,231,235,239],{"title":10,"path":112,"stem":116},"4.reference\u002Findex",{"title":118,"path":119,"stem":120,"children":121},"CLI","\u002Freference\u002Fcli","4.reference\u002F1.cli\u002Findex",[122,123,127,131,135],{"title":10,"path":119,"stem":120},{"title":124,"path":125,"stem":126},"Item verbs","\u002Freference\u002Fcli\u002Fitem","4.reference\u002F1.cli\u002F2.item",{"title":128,"path":129,"stem":130},"View verbs","\u002Freference\u002Fcli\u002Fview","4.reference\u002F1.cli\u002F3.view",{"title":132,"path":133,"stem":134},"Repo verbs","\u002Freference\u002Fcli\u002Frepo","4.reference\u002F1.cli\u002F4.repo",{"title":136,"path":137,"stem":138},"Admin verbs","\u002Freference\u002Fcli\u002Fadmin","4.reference\u002F1.cli\u002F5.admin",{"title":140,"path":141,"stem":142,"children":143},"Configuration","\u002Freference\u002Fconfiguration","4.reference\u002F2.configuration\u002Findex",[144,145,155,159,163,167,171,175,179],{"title":10,"path":141,"stem":142},{"title":146,"path":147,"stem":148,"children":149},"Repos","\u002Freference\u002Fconfiguration\u002Frepos","4.reference\u002F2.configuration\u002F2.repos\u002Findex",[150,151],{"title":10,"path":147,"stem":148},{"title":152,"path":153,"stem":154},"Workspaces","\u002Freference\u002Fconfiguration\u002Frepos\u002Fworkspaces","4.reference\u002F2.configuration\u002F2.repos\u002F3.workspaces",{"title":156,"path":157,"stem":158},"Policy","\u002Freference\u002Fconfiguration\u002Fpolicy","4.reference\u002F2.configuration\u002F3.policy",{"title":160,"path":161,"stem":162},"Library and chains","\u002Freference\u002Fconfiguration\u002Flibrary-and-chains","4.reference\u002F2.configuration\u002F4.library-and-chains",{"title":164,"path":165,"stem":166},"Harnesses file","\u002Freference\u002Fconfiguration\u002Fharnesses-file","4.reference\u002F2.configuration\u002F5.harnesses-file",{"title":168,"path":169,"stem":170},"Access","\u002Freference\u002Fconfiguration\u002Faccess","4.reference\u002F2.configuration\u002F6.access",{"title":172,"path":173,"stem":174},"Intake","\u002Freference\u002Fconfiguration\u002Fintake","4.reference\u002F2.configuration\u002F7.intake",{"title":176,"path":177,"stem":178},"Sandbox host","\u002Freference\u002Fconfiguration\u002Fsandbox","4.reference\u002F2.configuration\u002F8.sandbox",{"title":180,"path":181,"stem":182},"Environment variables","\u002Freference\u002Fconfiguration\u002Fenvironment-variables","4.reference\u002F2.configuration\u002F9.environment-variables",{"title":184,"path":185,"stem":186,"children":187},"Chain nodes","\u002Freference\u002Fchain-nodes","4.reference\u002F3.chain-nodes\u002Findex",[188,189,193,197],{"title":10,"path":185,"stem":186},{"title":190,"path":191,"stem":192},"Subprocess tasks","\u002Freference\u002Fchain-nodes\u002Fsubprocess-tasks","4.reference\u002F3.chain-nodes\u002F2.subprocess-tasks",{"title":194,"path":195,"stem":196},"Fix loop and judge","\u002Freference\u002Fchain-nodes\u002Ffix-loop","4.reference\u002F3.chain-nodes\u002F3.fix-loop",{"title":198,"path":199,"stem":200},"Result file","\u002Freference\u002Fchain-nodes\u002Fresult-file","4.reference\u002F3.chain-nodes\u002F4.result-file",{"title":202,"path":203,"stem":204},"Permission gate","\u002Freference\u002Fpermissions","4.reference\u002F4.permissions",{"title":206,"path":207,"stem":208,"children":209},"Agent harnesses","\u002Freference\u002Fharnesses","4.reference\u002F5.harnesses\u002Findex",[210,211,215,219,223],{"title":10,"path":207,"stem":208},{"title":212,"path":213,"stem":214},"Unattended runs","\u002Freference\u002Fharnesses\u002Funattended-runs","4.reference\u002F5.harnesses\u002F2.unattended-runs",{"title":216,"path":217,"stem":218},"Agent profiles","\u002Freference\u002Fharnesses\u002Fagent-profiles","4.reference\u002F5.harnesses\u002F3.agent-profiles",{"title":220,"path":221,"stem":222},"Harness files","\u002Freference\u002Fharnesses\u002Fharness-files","4.reference\u002F5.harnesses\u002F4.harness-files",{"title":224,"path":225,"stem":226},"Fallback and escalation","\u002Freference\u002Fharnesses\u002Ffallback-and-escalation","4.reference\u002F5.harnesses\u002F5.fallback-and-escalation",{"title":228,"path":229,"stem":230},"Inbound triggers","\u002Freference\u002Ftriggers","4.reference\u002F6.triggers",{"title":232,"path":233,"stem":234},"HTTP API","\u002Freference\u002Fhttp-api","4.reference\u002F7.http-api",{"title":236,"path":237,"stem":238},"MCP tools","\u002Freference\u002Fmcp-tools","4.reference\u002F8.mcp-tools",{"title":240,"path":241,"stem":242},"Events","\u002Freference\u002Fevents","4.reference\u002F9.events",{"title":244,"path":245,"stem":246,"children":247},"Project","\u002Fproject","5.project",[248,250,254,258,262,266],{"title":10,"path":245,"stem":249},"5.project\u002Findex",{"title":251,"path":252,"stem":253},"Architecture","\u002Fproject\u002Farchitecture","5.project\u002F1.architecture",{"title":255,"path":256,"stem":257},"Contributing","\u002Fproject\u002Fcontributing","5.project\u002F2.contributing",{"title":259,"path":260,"stem":261},"Security","\u002Fproject\u002Fsecurity","5.project\u002F3.security",{"title":263,"path":264,"stem":265},"Data and privacy","\u002Fproject\u002Fdata-and-privacy","5.project\u002F4.data-and-privacy",{"title":267,"path":268,"stem":269},"Status and support","\u002Fproject\u002Fstatus-and-support","5.project\u002F5.status-and-support",{"id":271,"title":263,"body":272,"description":773,"extension":774,"links":775,"meta":776,"navigation":777,"path":264,"seo":778,"stem":265,"__hash__":779},"docs\u002F5.project\u002F4.data-and-privacy.md",{"type":273,"value":274,"toc":765},"minimark",[275,279,284,287,301,305,486,501,505,520,719,731,745,749],[276,277,278],"p",{},"Kraft has no telemetry. It sends no usage data, crash reports or analytics\nanywhere. The outbound calls it makes are listed below, and each one serves a\nfeature you can see.",[280,281,283],"h2",{"id":282},"model-providers","Model providers",[276,285,286],{},"Kraft never calls a model API itself. It runs the agent CLI you installed,\nsuch as Claude Code, and that CLI sends your code, prompts and tool output to\nits provider under your account and that provider's terms. What the provider\nkeeps and for how long is set by your account with it, not by Kraft.",[276,288,289,290,295,296,300],{},"Under a ",[291,292,294],"a",{"href":293},"\u002Freference\u002Fconfiguration\u002Frepos#sandboxed-workers","sandbox"," with a\n",[297,298,299],"code",{},"network:"," policy, the agent's traffic leaves through Kraft's own egress\nproxy, and only to the hosts the policy and the harness allow.",[280,302,304],{"id":303},"outbound-calls","Outbound calls",[306,307,308,327],"table",{},[309,310,311],"thead",{},[312,313,314,318,321,324],"tr",{},[315,316,317],"th",{},"Call",[315,319,320],{},"Goes to",[315,322,323],{},"When",[315,325,326],{},"Turn it off",[328,329,330,348,378,401,422,444,461],"tbody",{},[312,331,332,336,342,345],{},[333,334,335],"td",{},"Agent CLI",[333,337,338,339],{},"Its provider, such as ",[297,340,341],{},"api.anthropic.com",[333,343,344],{},"Every agent task",[333,346,347],{},"Not applicable: this is the work.",[312,349,350,353,359,373],{},[333,351,352],{},"Update check",[333,354,355,358],{},[297,356,357],{},"api.github.com",", this project's releases list",[333,360,361,364,365,368,369,372],{},[297,362,363],{},"kraft admin start"," and ",[297,366,367],{},"kraft admin doctor",", at most once a day (cached in ",[297,370,371],{},"run\u002Fupdate-check.json",")",[333,374,375],{},[297,376,377],{},"KRAFT_NO_UPDATE_CHECK=1",[312,379,380,385,395,398],{},[333,381,382],{},[297,383,384],{},"kraft admin update",[333,386,387,388,391,392],{},"The release's wheel on GitHub, then ",[297,389,390],{},"uv tool install"," (PyPI for dependencies) or ",[297,393,394],{},"brew upgrade",[333,396,397],{},"Only when you run it",[333,399,400],{},"Don't run it.",[312,402,403,413,416,419],{},[333,404,405,406,409,410,372],{},"Forge CLI (",[297,407,408],{},"gh",", ",[297,411,412],{},"glab",[333,414,415],{},"Your forge",[333,417,418],{},"Merge-request nodes: open, read checks and reviews, mark ready, merge",[333,420,421],{},"A chain without merge-request nodes makes none.",[312,423,424,432,438,441],{},[333,425,426,409,429],{},[297,427,428],{},"git fetch",[297,430,431],{},"git push",[333,433,434,435],{},"Your repo's ",[297,436,437],{},"origin",[333,439,440],{},"Fetching the base branch, and pushing the item's branch",[333,442,443],{},"Not applicable.",[312,445,446,449,455,458],{},[333,447,448],{},"Notifications",[333,450,451,452],{},"The webhook URL in ",[297,453,454],{},"notify.yaml",[333,456,457],{},"The events you chose, only while notifications are on",[333,459,460],{},"Off by default.",[312,462,463,466,473,480],{},[333,464,465],{},"Embedding model",[333,467,468,469,472],{},"Hugging Face, ",[297,470,471],{},"Qdrant\u002Fbge-small-en-v1.5-onnx-Q",", about 130 MB",[333,474,475,476,479],{},"The first vector index or search, only with the ",[297,477,478],{},"vector"," extra installed",[333,481,482,483,485],{},"Don't install the ",[297,484,478],{}," extra.",[276,487,488,489,492,493,496,497,500],{},"The forge CLI and ",[297,490,491],{},"git"," calls use your own logins for those tools. The\nembedding model is cached in ",[297,494,495],{},"~\u002F.cache\u002Fkraft\u002Ffastembed",", or in\n",[297,498,499],{},"$KRAFT_EMBED_CACHE"," if you set it.",[280,502,504],{"id":503},"secrets-and-state","Secrets and state",[276,506,507,508,511,512,515,516,519],{},"Everything lives under ",[297,509,510],{},"$KRAFT_HOME"," (default ",[297,513,514],{},"~\u002F.kraft","). Kraft writes its\nconfig files through a temporary file created with mode ",[297,517,518],{},"0600",", so a file\nKraft has written is readable only by you. A file you created or edited by\nhand keeps its own mode.",[306,521,522,535],{},[309,523,524],{},[312,525,526,529,532],{},[315,527,528],{},"What",[315,530,531],{},"Where",[315,533,534],{},"Mode",[328,536,537,552,570,590,604,627,643,658,672,691,704],{},[312,538,539,542,547],{},[333,540,541],{},"Settings password (scrypt hash) and bind",[333,543,544],{},[297,545,546],{},"templates\u002Faccess.yaml",[333,548,549,551],{},[297,550,518],{}," once Kraft writes it",[312,553,554,557,562],{},[333,555,556],{},"Bearer token for the CLI and MCP",[333,558,559],{},[297,560,561],{},"run\u002Fmcp-token",[333,563,564,566,567,569],{},[297,565,518],{},"; ",[297,568,367],{}," checks it",[312,571,572,579,584],{},[333,573,574,575,578],{},"Bearer token for ",[297,576,577],{},"POST \u002Fapi\u002Ftriggers"," only",[333,580,581],{},[297,582,583],{},"run\u002Ftrigger-token",[333,585,586,566,588,569],{},[297,587,518],{},[297,589,367],{},[312,591,592,595,600],{},[333,593,594],{},"Notification webhook URL",[333,596,597],{},[297,598,599],{},"templates\u002Fnotify.yaml",[333,601,602,551],{},[297,603,518],{},[312,605,606,613,618],{},[333,607,608,609,612],{},"Repo ",[297,610,611],{},"env:"," values",[333,614,615],{},[297,616,617],{},"templates\u002Frepos.yaml",[333,619,620,622,623,626],{},[297,621,518],{}," once Kraft writes it (",[297,624,625],{},"kraft repo connect"," or a Settings save)",[312,628,629,632,637],{},[333,630,631],{},"Everything below",[333,633,634],{},[297,635,636],{},"run\u002F",[333,638,639,642],{},[297,640,641],{},"0700","; Kraft sets it on every start",[312,644,645,648,653],{},[333,646,647],{},"Login sessions (token hashes), work items, events",[333,649,650],{},[297,651,652],{},"run\u002Forchestrator.db",[333,654,655,657],{},[297,656,518],{}," when Kraft creates it",[312,659,660,663,668],{},[333,661,662],{},"Search index of specs, plans and other documents",[333,664,665],{},[297,666,667],{},"run\u002Findex.db",[333,669,670,657],{},[297,671,518],{},[312,673,674,677,682],{},[333,675,676],{},"Agent logs",[333,678,679],{},[297,680,681],{},"run\u002Flogs\u002F",[333,683,684,686,687,690],{},[297,685,518],{}," for a session log; ",[297,688,689],{},"server.log"," has your default file mode",[312,692,693,696,701],{},[333,694,695],{},"Agent results",[333,697,698],{},[297,699,700],{},"run\u002Fresults\u002F",[333,702,703],{},"Your default file mode",[312,705,706,709,717],{},[333,707,708],{},"Attachment copies and worktrees",[333,710,711,409,714],{},[297,712,713],{},"run\u002Fattachments\u002F",[297,715,716],{},"run\u002Fworktrees\u002F",[333,718,703],{},[276,720,721,722,724,725,727,728,730],{},"Agent logs hold whole sessions: prompts, the code the agent read and wrote,\nand command output. Because ",[297,723,636],{}," is ",[297,726,641],{},", other users on the machine cannot\nreach anything inside it, whatever mode a file has. A database created by an\nolder Kraft keeps its mode. Treat ",[297,729,636],{}," like the repositories it works on.",[276,732,733,734,736,737,740,741,744],{},"A repo's ",[297,735,611],{}," values go into each worker's process environment, not onto\nits command line. Your own user and root can read them there, for example\nwith ",[297,738,739],{},"ps eww"," on macOS or from ",[297,742,743],{},"\u002Fproc\u002F\u003Cpid>\u002Fenviron"," on Linux. Every agent\nrunning for that repo can read them too.",[280,746,748],{"id":747},"related","Related",[750,751,752,758],"ul",{},[753,754,755,757],"li",{},[291,756,259],{"href":260},": the default posture and the threat model.",[753,759,760,764],{},[291,761,763],{"href":762},"\u002Fproject\u002Fsecurity#the-bearer-token","The bearer token",": what it grants and\nhow to rotate it.",{"title":766,"searchDepth":767,"depth":767,"links":768},"",2,[769,770,771,772],{"id":282,"depth":767,"text":283},{"id":303,"depth":767,"text":304},{"id":503,"depth":767,"text":504},{"id":747,"depth":767,"text":748},"What leaves your machine, where it goes, how to turn it off, and where Kraft keeps secrets and state.","md",null,{},true,{"title":263,"description":773},"8KvXTkBhA4q4bFcLqnp__192yVZXyfshnRFSmsbUnAY",[781,783],{"title":259,"path":260,"stem":261,"description":782,"children":-1},"Kraft's threat model: what it protects against, and what it deliberately doesn't.",{"title":267,"path":268,"stem":269,"description":784,"children":-1},"How mature Kraft is, what its version numbers promise, where it runs, and where to get help.",1790824542663]