This site is being rebuilt and some pages are out of date. For current details, write to [email protected]. This notice goes away when the rebuild is done.

No analytics unless you allow it, no tracking. This site keeps in your browser the language you pick, the theme, its colour, which site you chose, the currency on the pricing page and that you closed this notice; signing in adds session cookies. The legal page has the details.

Sign in

Tools

The command line, the SDKs and the agent

iohr signs you in, calls the API, generates a client cut to what your credentials may call, and installs extensions. The client libraries cover Rust, TypeScript, Python and Go. The agent runs checks inside your own network and sends back timings and verdicts, never the content.

A preview. Everything here is a pre-release or a 0.x version, so commands and output can still change. Versions as checked on 2026-10-07.

01The command line

One binary, iohr. It keeps several accounts as profiles, creates and revokes API tokens, and talks only to api.inorbit.hr and auth.inorbit.hr, with no telemetry and no update check. Secrets go to the operating system's credential store.

Homebrew · macOS, Linux

bash
brew install inorbithr/tap/iohr

APT · Debian, Ubuntu

bash
sudo install -d -m 0755 /etc/apt/keyrings
curl -fsSL https://packages.inorbit.hr/iohr.gpg | sudo tee /etc/apt/keyrings/iohr.gpg >/dev/null
printf 'Types: deb\nURIs: https://packages.inorbit.hr/apt\nSuites: stable\nComponents: main\nSigned-By: /etc/apt/keyrings/iohr.gpg\n' \
  | sudo tee /etc/apt/sources.list.d/iohr.sources >/dev/null
sudo apt update && sudo apt install iohr

Installer, no sudo · Linux, macOS

bash
curl -fsSL https://packages.inorbit.hr/install.sh | sh

PowerShell, no administrator · Windows

powershell
powershell -c "irm https://packages.inorbit.hr/install.ps1 | iex"

The APT repository is signed by the key with fingerprint 5FF6 7AF3 D50A 6B06 FFE6 EA8A FFA5 11CF 585B F28D.

winget follows with the first stable release, under the id InOrbit.iohr.

Then

bash
iohr login
iohr whoami
iohr api GET /v1/me

iohr login opens your browser, or prints a link and a code over SSH.

Every release carries checksums, an SBOM and build provenance you can check with gh attestation verify. The installers check the checksum before they copy anything. Verifying a release
02The SDKs

One runtime per language, with the same behaviour everywhere: an API token or a key exchanged for a short-lived token and refreshed, typed results, one error type carrying the API's code, and retries only where a retry is safe. One set of conformance cases runs against all of them.

  • RustVersion 0.2.2

    inorbithr

    With iohr
    bash
    iohr sdk add rust
    Or with the package manager
    bash
    cargo add inorbithr
    Needs: Rust 1.94crates.io
  • TypeScriptVersion 0.2.2

    @inorbithr/sdk

    With iohr
    bash
    iohr sdk add typescript
    Or with the package manager
    bash
    npm install @inorbithr/sdk
    Needs: Node 22.12, Bun, Deno, browsersnpm and JSR
  • PythonVersion 0.2.2

    inorbithr

    With iohr
    bash
    iohr sdk add python
    Or with the package manager
    bash
    pip install inorbithr
    Needs: Python 3.11PyPI
  • GoVersion 0.2.3

    github.com/inorbithr/sdk/go

    With iohr
    bash
    iohr sdk add go
    Or with the package manager
    bash
    go get github.com/inorbithr/sdk/go@latest
    Needs: Go 1.26pkg.go.dev
  • C#Version 0.2.2

    InOrbit.Sdk

    Tagged and built from source. The registry release comes later.

    Needs: .NET 8
  • JavaVersion 0.2.2

    hr.inorbit:inorbit-sdk

    Tagged and built from source. The registry release comes later.

    Needs: Java 17

Add the SDK to a project

In a project, iohr sdk add finds the language and the package manager the project already uses (its lock file, packageManager, an active virtualenv) and runs that manager for you: cargo add, pnpm add, uv add, go get and the rest. It prints the command before it runs it; --dry-run stops there and --version pins one release. It never runs a shell or sudo.

bash
cd your-project
iohr sdk add --dry-run
iohr sdk add

A client cut to your account

iohr sdk generate writes only the operations your profile's credential may call, in any of the six languages, so a call it may not make fails to compile (in Python, the type checker refuses it). Commit it with iohr.lock and run iohr sdk check in CI: it fails with a diff when what the credential may call changes.

bash
iohr login
iohr sdk generate --lang rust --for default --out src/iohr
iohr sdk check
03Extensions

An extension is a separate program that iohr installs from an OCI registry, verifies, pins and runs. Before anything is used, iohr checks every digest, the signature and the SLSA provenance from InOrbit's release workflow, offline against the Sigstore root built into it; no flag skips this. What is installed is pinned in iohr-ext.lock, and nothing updates until you run iohr ext upgrade. The first extension is the agent.

bash
iohr ext install agent
iohr ext list
iohr ext verify
Read the docs
04Browser extension

InOrbit Trails records your own session on sites you allow, one at a time: the pages, what you click, how far you scroll, timings and errors. Never what you type. Recordings stay in your browser until you sign in and press Upload. For Chrome, Edge, Vivaldi, Brave, Opera and Firefox.

05The agent

iohr-agent runs checks for the platform inside your network, where the systems are. It dials out over one WebSocket and listens on nothing, so there is no inbound firewall rule to ask for. It makes its own key on the machine at enrollment, does only what a local policy file allows, and reads a credential from your vault or cluster at the moment of a call and forgets it after.

  • Checks today: http (status, latency, certificate expiry), tcp, tls and grpc_health. Load and faults come later and are refused until then.
  • A checks.toml declares what it watches; the platform turns each check into a monitor managed by that agent.
  • It sends timings, status codes and verdicts. Never a request or response body, a header value or a secret.
  • Linux and macOS, amd64 and arm64; a container image and a Helm chart for Kubernetes.

As an iohr extension

bash
iohr ext install agent
iohr agent init
iohr agent run

Kubernetes, Helm

bash
kubectl create namespace iohr-agent
kubectl -n iohr-agent create secret generic iohr-agent-enrollment --from-literal=token=ioe_...
helm install agent oci://ghcr.io/inorbithr/charts/iohr-agent --version 0.1.0-alpha.7 \
  --namespace iohr-agent \
  --set environment=staging \
  --set enrollment.existingSecret=iohr-agent-enrollment \
  -f my-values.yaml

Debian, Ubuntu, RHEL, Fedora

bash
sudo apt install ./iohr-agent_0.1.0.alpha.7-1_amd64.deb
# or: sudo dnf install ./iohr-agent-0.1.0.alpha.7-1.x86_64.rpm
sudoedit /etc/iohr-agent/agent.toml /etc/iohr-agent/policy.toml
sudo systemctl enable --now iohr-agent

Enrolling needs a one-time token. The console makes one for the environment and the verified domains you name, and shows the commands with it.

Enroll an agent

Every artifact is signed keyless by the release workflow at its tag, with SLSA provenance and a CycloneDX SBOM. A package is checked like this:

bash
gh attestation verify iohr-agent_0.1.0.alpha.7-1_amd64.deb --repo inorbithr/dataplane
sha256sum -c SHA256SUMS
Verifying a release