SessionStart hook that provisions a short-lived, policy-scoped OpenBao token for each agent session. For Claude Code it writes export lines into $CLAUDE_ENV_FILE; for hosts that cannot persist env from hooks (Codex) it writes a mode-600 session env file and points the agent to it via context. Failure degrades to a benign JSON so sessions still start. Registered in both Claude and Codex marketplace manifests. Co-Authored-By: Claude <noreply@anthropic.com>
21 lines
765 B
JSON
21 lines
765 B
JSON
{
|
|
"name": "openbao-session",
|
|
"version": "0.1.0+codex.20260901021149",
|
|
"description": "Provisions a short-lived OpenBao session token for interactive agent sessions.",
|
|
"author": {
|
|
"name": "Local developer"
|
|
},
|
|
"hooks": "./hooks/claude-codex-hooks.json",
|
|
"interface": {
|
|
"displayName": "OpenBao Session",
|
|
"shortDescription": "Automatic OpenBao session token provisioning.",
|
|
"longDescription": "At session start, opens a loopback SSH tunnel to OpenBao and injects a short-lived, scoped session token so the agent can read only the secrets its policy permits.",
|
|
"developerName": "Local developer",
|
|
"category": "Security",
|
|
"capabilities": [
|
|
"Lifecycle hooks"
|
|
],
|
|
"defaultPrompt": "Help me use OpenBao Session."
|
|
}
|
|
}
|