Skip to content
OpenFirma
Search
Ctrl
K
Cancel
GitHub
RSS
Blog
Select theme
Dark
Light
Auto
Blog
Start Here
Overview
Quickstart
Concepts
Architecture & invariants
The enforcement pipeline
Action classes
Capabilities
Policies
Interception
Connectors
The sandbox boundary
Threat model & bypasses
User Guides
Initialize a project (firma config)
Run the sidecar standalone
Inspect live sidecars (firma sidecar status)
Start & monitor the daemon (firma sidecar & monitor)
Diagnose with firma doctor
Write your first Cedar policy
Test policies offline (firma policy)
Issue capability tokens
Wrap an agent with firma run
Enable HTTPS MITM
Extend the action-class mapping
Inject credentials
Read & verify the audit log
Secure a local coding agent
Secure GitHub Copilot CLI
Secure Visual Studio Code
Deploy a GenAI web app
Rust API Reference
Rust API Reference
firma_authority
firma-authority
Crate root
authorized_clients
cedar_loader
config
issuance
keygen
profiles
profiles
developer
revocation
revocation
RevocationStore
seed
server
service
startup
startup
log_contract
tls_verifier
firma_config_loader
firma_config_loader
Crate root
profile
resolver
resolver
ConfigResolver
schema
schema
FirmaConfig
firma_core
firma-core
Crate root
action_class
action_class
ActionClass
agent_id
capability_seed
cedar
connector
credential
decision
envelope
policy
run_audit
session
token
token
paseto
TokenId
transport
firma_demo_fixture
firma-demo-fixture
Crate root
firma_fs
firma_fs
Crate root
FsError
firma_grpc_interceptor_proto
firma-grpc-interceptor-proto
Crate root
firma
firma
interceptor
interceptor
v1
v1
interceptor_hook_client
interceptor_hook_server
firma_http
firma_http
header_name
method
firma_run
firma-run
Crate root
authority
authority
bootstrap
config
prompt
selection
supervisor
backend
backend
firecracker
linux_bwrap
macos_vz
platform
windows_wsl2
capability
capability
guard
issue
refresh
config
dns_stub
dns_stub
HostDnsStubHandle
egress_guard
error
identity
log
log
ForegroundLog
ForegroundState
mediator
proxy_bridge
routing
runtime
seccomp
sidecar
sidecar
selection
supervisor
firma_runtime_state
firma_runtime_state
Crate root
error
pidfile
process_id
process_id
child_ext
runtime_paths
sandbox_id
sidecar_markers
state_dir
status
firma_sidecar
firma-sidecar
Crate root
audit
audit
builder
builder
EventBuilder
sink
file
grpc
stdout
wal
authority_client
authority_client
backoff
channel
policy_bundle
readiness
revocation
swappable_policy
authority_credentials
config
config
audit
authority
capability_seed
connector
enforcement
revocation
SidecarConfig
tenancy
connector
connector
provider
http
http
GenericHttpConnector
registry
registry
ConnectorRegistry
credential
credential
provider
provider
basic
composite
vault
enforcement
enforcement
capability_map
capability_validation
cedar_evaluator
constraint_enforcement
constraint_enforcement
ConstraintEnforcer
decision
error
error
EnforcementError
registry
revocation
revocation
metrics
session
session
persistent
state
handler
handler
RequestHandler
health
interceptor
interceptor
grpc
http
unix_socket
local_exec
local_exec
endpoint
endpoint
LocalExecEndpoint
handler
handler
LocalExecHandler
token_store
normalizer
normalizer
mapping
pipeline
run_audit
startup
startup
audit
authority
capability
connector
credential
interceptor
local_exec
log_contract
pipeline
firma_stack
firma_stack
Crate root
config
error
shutdown_event
start
status
stop
firma_tui
firma_tui
Crate root
control
control
announcement
app
bindings
command
error
event
input
render
runner
state
state
audit
runtime
status
GitHub
RSS
Blog
Select theme
Dark
Light
Auto
firma_http
firma_http
Section titled “firma_http”
Modules
Section titled “Modules”
header_name
Section titled “header_name”
1 struct
method
Section titled “method”
1 struct