Tools
The command line, the SDKs and the agent
iohr signs you in, calls the API, generates a client cut to what your credentials may call, and installs extensions. The client libraries cover Rust, TypeScript, Python and Go. The agent runs checks inside your own network and sends back timings and verdicts, never the content.
A preview. Everything here is a pre-release or a 0.x version, so commands and output can still change. Versions as checked on 2026-10-07.
One binary, iohr. It keeps several accounts as profiles, creates and revokes API tokens, and talks only to api.inorbit.hr and auth.inorbit.hr, with no telemetry and no update check. Secrets go to the operating system's credential store.
Homebrew · macOS, Linux
brew install inorbithr/tap/iohrAPT · Debian, Ubuntu
sudo install -d -m 0755 /etc/apt/keyrings
curl -fsSL https://packages.inorbit.hr/iohr.gpg | sudo tee /etc/apt/keyrings/iohr.gpg >/dev/null
printf 'Types: deb\nURIs: https://packages.inorbit.hr/apt\nSuites: stable\nComponents: main\nSigned-By: /etc/apt/keyrings/iohr.gpg\n' \
| sudo tee /etc/apt/sources.list.d/iohr.sources >/dev/null
sudo apt update && sudo apt install iohrInstaller, no sudo · Linux, macOS
curl -fsSL https://packages.inorbit.hr/install.sh | shPowerShell, no administrator · Windows
powershell -c "irm https://packages.inorbit.hr/install.ps1 | iex"The APT repository is signed by the key with fingerprint 5FF6 7AF3 D50A 6B06 FFE6 EA8A FFA5 11CF 585B F28D.
winget follows with the first stable release, under the id InOrbit.iohr.
Then
iohr login
iohr whoami
iohr api GET /v1/meiohr login opens your browser, or prints a link and a code over SSH.
One runtime per language, with the same behaviour everywhere: an API token or a key exchanged for a short-lived token and refreshed, typed results, one error type carrying the API's code, and retries only where a retry is safe. One set of conformance cases runs against all of them.
- RustVersion 0.2.2
inorbithr
With iohrbashiohr sdk add rustOr with the package managerbashcargo add inorbithrNeeds: Rust 1.94crates.io - TypeScriptVersion 0.2.2
@inorbithr/sdk
With iohrbashiohr sdk add typescriptOr with the package managerbashnpm install @inorbithr/sdkNeeds: Node 22.12, Bun, Deno, browsersnpm and JSR - PythonVersion 0.2.2
inorbithr
With iohrbashiohr sdk add pythonOr with the package managerbashpip install inorbithrNeeds: Python 3.11PyPI - GoVersion 0.2.3
github.com/inorbithr/sdk/go
With iohrbashiohr sdk add goOr with the package managerbashgo get github.com/inorbithr/sdk/go@latestNeeds: Go 1.26pkg.go.dev - C#Version 0.2.2
InOrbit.Sdk
Tagged and built from source. The registry release comes later.
Needs: .NET 8 - JavaVersion 0.2.2
hr.inorbit:inorbit-sdk
Tagged and built from source. The registry release comes later.
Needs: Java 17
Add the SDK to a project
In a project, iohr sdk add finds the language and the package manager the project already uses (its lock file, packageManager, an active virtualenv) and runs that manager for you: cargo add, pnpm add, uv add, go get and the rest. It prints the command before it runs it; --dry-run stops there and --version pins one release. It never runs a shell or sudo.
cd your-project
iohr sdk add --dry-run
iohr sdk addA client cut to your account
iohr sdk generate writes only the operations your profile's credential may call, in any of the six languages, so a call it may not make fails to compile (in Python, the type checker refuses it). Commit it with iohr.lock and run iohr sdk check in CI: it fails with a diff when what the credential may call changes.
iohr login
iohr sdk generate --lang rust --for default --out src/iohr
iohr sdk checkAn extension is a separate program that iohr installs from an OCI registry, verifies, pins and runs. Before anything is used, iohr checks every digest, the signature and the SLSA provenance from InOrbit's release workflow, offline against the Sigstore root built into it; no flag skips this. What is installed is pinned in iohr-ext.lock, and nothing updates until you run iohr ext upgrade. The first extension is the agent.
iohr ext install agent
iohr ext list
iohr ext verifyInOrbit Trails records your own session on sites you allow, one at a time: the pages, what you click, how far you scroll, timings and errors. Never what you type. Recordings stay in your browser until you sign in and press Upload. For Chrome, Edge, Vivaldi, Brave, Opera and Firefox.
iohr-agent runs checks for the platform inside your network, where the systems are. It dials out over one WebSocket and listens on nothing, so there is no inbound firewall rule to ask for. It makes its own key on the machine at enrollment, does only what a local policy file allows, and reads a credential from your vault or cluster at the moment of a call and forgets it after.
- Checks today: http (status, latency, certificate expiry), tcp, tls and grpc_health. Load and faults come later and are refused until then.
- A checks.toml declares what it watches; the platform turns each check into a monitor managed by that agent.
- It sends timings, status codes and verdicts. Never a request or response body, a header value or a secret.
- Linux and macOS, amd64 and arm64; a container image and a Helm chart for Kubernetes.
As an iohr extension
iohr ext install agent
iohr agent init
iohr agent runKubernetes, Helm
kubectl create namespace iohr-agent
kubectl -n iohr-agent create secret generic iohr-agent-enrollment --from-literal=token=ioe_...
helm install agent oci://ghcr.io/inorbithr/charts/iohr-agent --version 0.1.0-alpha.7 \
--namespace iohr-agent \
--set environment=staging \
--set enrollment.existingSecret=iohr-agent-enrollment \
-f my-values.yamlDebian, Ubuntu, RHEL, Fedora
sudo apt install ./iohr-agent_0.1.0.alpha.7-1_amd64.deb
# or: sudo dnf install ./iohr-agent-0.1.0.alpha.7-1.x86_64.rpm
sudoedit /etc/iohr-agent/agent.toml /etc/iohr-agent/policy.toml
sudo systemctl enable --now iohr-agentEnrolling needs a one-time token. The console makes one for the environment and the verified domains you name, and shows the commands with it.
Enroll an agentEvery artifact is signed keyless by the release workflow at its tag, with SLSA provenance and a CycloneDX SBOM. A package is checked like this:
gh attestation verify iohr-agent_0.1.0.alpha.7-1_amd64.deb --repo inorbithr/dataplane
sha256sum -c SHA256SUMS