Configure push and CI capture
On each captured GitHub repository, create four webhooks. Set each content type toapplication/json and each secret to SEDIMENT_GITHUB_WEBHOOK_SECRET from
the server’s ~/.sediment/server/server.env:
In each webhook’s Recent Deliveries, the setup ping returns
200 with a
skipped reason. A 401 means a missing or wrong secret. A redelivery returns
"stored": false, which is a success: the server already has that Fact. The
API reference lists the supported events.
GitHub doesn’t retry failed deliveries. After an outage or a DNS change, check
Recent Deliveries, and
redeliver the failed events.
For another CI system, send normalized results to
POST /ingest/ci with a capture token.
Only passed and failed count as verdicts. Sediment trusts the sender’s
provider identity.
Configure repository mirrors
Commit Attribution reads the git notes from a mirror that the server fetches after each Push. For a private repository, give the server account read-only Git credentials, through its credential manager or a~/.netrc file with mode
0600:
session_commit_observations_captured with a nonzero
count for that repository, and the
forge check lists the Session.
If the log shows repository_mirror_identity_unresolved, inspect the stored
repository identities before you redeliver the Push.
Configure inference-call capture
A gateway sends a copy of each successful model call toPOST /ingest/gateway. Sediment
doesn’t serve model requests, and the published package doesn’t include a
gateway.
Sediment reads the LiteLLM callback payload. To add the callback to your own
LiteLLM proxy, follow
Connect an existing LiteLLM gateway.
Another gateway needs an integration that sends the same envelope.
For each gateway:
- Give it a capture token and the HTTPS API URL. Keep provider keys on the gateway.
- Keep each developer’s chosen model. Configure capture failures so they don’t fail the model call.
- Make sure the client carries the real Session identifier. The server skips
calls without one and logs
gateway_ingest_skipped_no_session. - Route each agent through the gateway, as described in Distribute gateway routing.
Distribute gateway routing
A gateway records only the model calls that an agent sends to it. Each agent needs the gateway URL and a client credential in the environment that starts it. Distribute both through configuration that you manage, such as MDM or an agent service.sediment install doesn’t configure gateway routing, and
developers don’t request a gateway credential.
Give each machine a client credential that the gateway accepts and that can’t
administer the gateway. The bundled LiteLLM gateway accepts only
LITELLM_MASTER_KEY, its administrative key, and can’t issue per-developer
keys. Keep that key on machines that you control.
Routed calls use the gateway’s provider key. While a gateway credential is
active, Claude Code doesn’t use the developer’s claude.ai subscription.
Claude Code
Merge the gateway route into the Claude Code managed settings file, and keep its other keys. The file is/Library/Application Support/ClaudeCode/managed-settings.json on macOS and
/etc/claude-code/managed-settings.json on Linux:
apiKeyHelper names a command that prints the client credential. Claude Code
sends its output in the Authorization and x-api-key headers, and reruns the
command after five minutes by default. The Claude desktop app reads gateway
routing from its own configuration, not from this file.
Codex
Codex needs a gateway with a Responses API route for the developer’s model. The bundled gateway serves onlyclaude-* models. Distribute these files:
-
A provider in
<Codex home>/config.toml: -
A
gatewayprofile in<Codex home>/gateway.config.tomlthat selects the provider and disables the image tool, which the LiteLLM bridge rejects: -
SEDIMENT_GATEWAY_KEYin the environment that starts Codex.
pi
Merge this provider into~/.pi/agent/models.json, and keep the existing
providers. Replace the URL and model ID, and copy the model’s capabilities,
context, and output limits from its existing definition:
SEDIMENT_GATEWAY_KEY in the environment that starts pi. Keep
$SEDIMENT_GATEWAY_KEY literally in the file; pi resolves it from the
environment. If you register a different provider name or API, also set
SEDIMENT_PROVIDER_ID and SEDIMENT_PROVIDER_API to match it.
Distribute decision telemetry
The fleet bundle installs commit Attribution hooks only. Distribute decision telemetry separately. For Claude Code, set this environment for each Claude Code process through shell profiles, MDM, or the agent’s service definition:OTEL_LOG_TOOL_DETAILS=1 lets Sediment record the file path of each edit.
Enroll the other agents on each machine with their guides:
Codex,
Cursor, and pi.
Build the fleet bundle
Generate the MDM payload:
The gitconfig fragment sets
init.templateDir and notes.rewriteRef, so every
later git clone and git init gets the hooks. Codex has no system-managed
settings file, so MDM merges its fragment into each user’s profile.
Set the owner allowlist
An agent can create a clone that no installer saw. The owner allowlist letssediment mark install hooks in your organization’s clones before their first
commit. Place config.json beside the fleet stamper:
Distribute the bundle
- Deploy the bundle, the system git configuration, the Claude Code managed settings, the Codex fragment, and the optional allowlist through MDM.
- For existing clones, run
git initin place to copy the template hooks, or runsediment installin each one.
sudo sediment install --fleet --apply.
If sudo resets your PATH, use the CLI’s absolute path. The command refuses
to overwrite an unrelated init.templateDir or an invalid managed-settings
file.
For an air-gapped fleet, build the bundle on a connected machine, and copy it to
the same prefix on each target. Preserve the hooks’ executable modes.
Transcript capture isn’t part of the bundle. Each user opts in with
Opt in to transcript capture.
Verify the rollout
Check each machine and agent combination, because totals can hide one broken client.-
Schedule the health check on each machine through MDM:
It exits with a failure when any installed integration is broken.
-
For each gateway and agent combination, run a short test Session. With an
operator token, query that Session’s captured calls:
The response lists the test call with the expected provider and model.
-
Check the other paths: Developer decisions grow after edits, the remote has
refs/notes/sedimentafter a push, Pushes and CI outcomes grow after forge events, and the API log reportsattributions_derivedafter a mirror refresh.
Remove managed capture
Remove managed capture in this order, so that the allowlist or a managed profile doesn’t reinstall something that you already removed:- Retire the MDM deployment policy, or switch it to removal mode. Keep the fleet prefix until nothing references it.
-
Delete the four GitHub webhooks. For another CI system, remove its
POST /ingest/cicall and its capture token. -
Remove each gateway’s Sediment callback and capture token. From client
machines, remove the gateway routing that you distributed: the Claude Code
ANTHROPIC_BASE_URLandapiKeyHelpersettings, the Codex provider and profile, the pi provider, andSEDIMENT_GATEWAY_KEY. Restart the agents. - Revoke the retired capture tokens. Never reuse a retired token for another client.
- Remove the distributed OpenTelemetry and pi variables from shell profiles, MDM, and agent services. Remove only Sediment’s telemetry blocks from Codex profiles, and restart the agents.
-
Remove
config.jsonfrom the fleet prefix, which turns off automatic installation. -
Remove Sediment’s
PostToolUseentry from the Claude Code managed settings and from each user’s Codex hooks file. Keep unrelated entries. -
Check the system git values:
If
init.templateDirpoints to the Sediment prefix, remove only the matching values. Replace/opt/sedimentif you chose another prefix: -
On each machine that used pi or transcript capture, run
Uninstall capture with
--agents. -
Run
sediment uninstall /path/to/repoin every other existing clone. - Remove the fleet prefix through MDM. When no captured private repository needs them, revoke the server’s mirror credentials.