See what your coding agent actually sends — and pay less for it.
Cortex sits in your agent's request path, decrypts its traffic, and shows you the model calls, tool calls and agent-to-agent messages as they happen. It can also strip the tool definitions your agent never calls, which is 4–20% of the prompt on every turn.
Think top, for your coding agent. Where top shows which processes are eating
your CPU, agentop observe shows which agent sessions are eating your tokens, your
context window and your money — live, as they run.
One binary, no Kubernetes. macOS or Linux, amd64 or arm64.
curl -fsSL https://raw.githubusercontent.com/rossoctl/cortex/main/scripts/install.sh \
| sh -s -- --claude-codeIt asks before changing your Claude Code settings, then runs Cortex as a background service that survives crashes and logins.
Then open two terminals:
agentop observe # the viewer
claude # as usual — no environment variables to setYour agent's calls stream into agentop. Cortex only reads them; nothing is rewritten.
- Cut token cost — one more command
- Start, stop, remove —
agentop service status | start | stop - Run it in Kubernetes — sidecars, Keycloak, SPIFFE/SPIRE
Any agent works, not only Claude Code (OpenCode has its
own agentop configure command): point it at localhost:47600 and trust
~/.cortex/ca/ca.crt.
curl | sh never executes unreleased code — the script re-runs the copy from the newest
release. Pin or override with --ref
(CONTRIBUTING.md).
Full install guide: Cortex on your laptop — prerequisites, step-by-step walkthrough, service management and troubleshooting.
agentop configure opencode disable --yes
agentop configure claude-code disable --yes && agentop service uninstall --yesThe first line is for OpenCode. It exits 1 when OpenCode is not installed, so it is a
line of its own rather than chained with &&.
Claude Code and OpenCode go straight to their APIs again, and Cortex stops and no longer
starts at login. Your config, CA and cost history stay in ~/.cortex, so
agentop service install && agentop configure claude-code enable brings it back as it was
(and agentop configure opencode enable for OpenCode).
Restart any claude that was already running: it still points at Cortex.
claude --resume picks the conversation back up. OpenCode needs no restart from you:
disable restarts its background service when it finds it running.
To delete everything, see Remove it. If
agentop itself is gone, remove it by hand.
Note
Cortex on a laptop is new, and we want to hear when it breaks.
If the install failed, the numbers looked wrong, or anything was unclear:
A half-finished install with the error pasted in is more useful to us than a polished bug report you never sent.
Traffic visibility is the part you can use in a minute. The same binary provides the platform services agentic workloads need in production, as a sidecar or standalone:
- Identity & access — a verifiable identity per workload, and the right credentials for each downstream call, so an agent never holds a tool's secret. This layer is AuthBridge.
- Guardrails — block agent actions that stray from the user's intent or aren't grounded in the conversation.
- Egress control — govern which external services a workload can reach.
- Cost controls — trim the context a workload sends, and cap its spend.
Everything is a plugin in one pipeline; the plugin catalog
lists what ships, and the architecture reference explains how
a request flows through it. The shared library is core/; the
binaries live under cmd/.