Coco

Installation

Two options. A hook installed with npx, or an SDK call against a gate that runs as a service.

Installation

Coco governs an agent that already exists, so where the check sits depends on which runtime that agent lives in. Two options, and both are current.

OptionThe check isChoose it when
npxA PreToolUse hook on the machineYour agent runs in Claude Code
SDKOne HTTP call from your harnessYour agent runs anywhere else

Both run the same gate file, the same contracts and the same ledger. See Architecture for where they converge.

Choosing

Take npx when the agent is a coding agent on a developer's machine or on a managed fleet. One command installs the hook, the agent's tool list does not change, and everything stays local. No account, no service to reach, and no network call on the decision path. The install command names the runtime, and a runtime with its own hooks, Cursor among them, runs the same gate as its hook. Claude Code is the example on every page.

Take the SDK when the agent runs on a platform, in a container, in a workflow builder, or anywhere without a terminal. That covers a framework harness too. In LangChain, the OpenAI Agents SDK or CrewAI, the check is one call at the place that executes tools. The gate answers over HTTP and your harness asks it one question before each action.

A team can take both. The developer machines take the hook, the production agents take the SDK, and both write receipts in the same shape.

The npx road

PageWhat it covers
npxThe install, its flags, what it writes, and how to verify it
Managed fleetInstalling it as policy rather than a developer preference
UninstallingRemoving the hook, and what happens to the ledger

The SDK road

PageWhat it covers
SDKThe two clients, the API, live state, and failure behaviour
HostedCoco runs the gate, from your policy documents to an enforcing check
Self-hostedYou run the container, for data that cannot leave your infrastructure

The hosted service is the faster road and most teams start there. The same image ships for a team that cannot use it.

Requirements

For npx, Node 18 or later runs the installer and python3 runs the gate. The gate uses the Python standard library only, so nothing is pip installed and there is no dependency tree for a security review to work through. The installer proves the interpreter it found actually runs before writing a hook that depends on it.

For the SDK, the Python client needs the standard library and the JavaScript client needs the fetch built into Node 18. Neither has a dependency beyond the language itself, and either file can be read in one sitting, which is the review.

The one place a dependency appears is turning YAML contracts into the JSON the gate reads. The installer does that in Node with a single YAML library, once, at install time. The gate that runs on every call is Python standard library only, and so are both SDK clients. The repository's benchmark and the contract-drafting tool need PyYAML, and neither sits on the decision path.

What the npm package contains

bin/          the coco command
installer/    install, uninstall, the YAML to JSON compiler
gate/         the hook, evaluator, ledger and rule language
sdk/          the Python and JavaScript clients
packs/        the baseline and session contracts, and the default mandate

Twenty-four files. The package deliberately does not carry the KYC or payments contract sets, because neither can fire for a coding agent and shipping them would add contracts that can only sit idle. Those live in the repository, along with the tests, the enforcement probe and the latency bench.

On this page