A local proxy that logs every Claude API call into a tamper-evident hash chain on your machine, with no cloud dependency. It sits between your AI coding agent and Anthropic's API, writing tool calls and responses to a local JSONL file you can cryptographically verify later using Sigstore attestations. The policy engine lets you block filesystem paths, detect secrets in real time, and set per-round token budgets before requests leave your network. When you need to prove what an agent did during a CI run, you bundle a session into a portable evidence file that verifies offline in one command, checking chain integrity, git state bindings, and signatures without touching the producer's machine. Useful if you're running autonomous agents in production and someone will eventually ask for an audit trail.
claude mcp add --transport stdio occasiolabs-occasio uvx occasio