First run: init and quickstart
The two first-run commands. defenseclaw init is the guided wizard and defenseclaw quickstart is the zero-prompt equivalent. Both run the same setup and print the same first-run report.
After the install, DefenseClaw is on disk but not configured yet. One first-run command configures it. There are two, and they do the same work with a different experience. For a guided first block, follow the 5-minute quickstart instead.
defenseclaw init
Interactive wizard. Asks about agents, profile, scanner mode, judge and HITL. Recommended the first time.
defenseclaw quickstart
Zero-prompt equivalent with safe defaults. Recommended for CI, scripts and demos.
You don't need to run init before quickstart. Both run the same first-run
setup: they write the config, create the audit database, configure the
guardrail and start the gateway. Pick one.
Native Windows
The same commands work on native Windows. Which agents you can set up there is
in the support matrix, and the
native Windows guide covers each connector's setup
notes. quickstart rejects a connector that isn't supported on Windows before
it writes anything.
Path A: interactive (defenseclaw init)
The recommended first run for a person at a terminal. The wizard walks you through every choice, shows the defaults and explains the trade-offs.
defenseclaw initOn a terminal this runs the guided wizard. It runs local agent discovery,
pre-selects every installed hook connector and configures them all in
observe (log-only) mode by default, so pressing Enter through the connector
prompt brings up everything you have. Rather than asking observe or action for
each one, it shows one checklist, Select connector(s) for action
enforcement, where you tick the agents that should block. Leave every box
unchecked and every connector stays in observe.
The action-only policy settings, the hook fail mode (open or closed) and
HITL human approval with its minimum severity, are asked once and shared by
every connector you promote to action. Observe connectors never see them.
Near the end the wizard asks Start gateway after setup? (default Yes,
because the hooks need a running gateway). --start-gateway or
--no-start-gateway answers it in advance. When you add the optional LLM judge
on AWS Bedrock, the wizard asks for the region and auth mode first, and asks for
an API key only for the api_key auth mode. On macOS, an OpenHands installed
with uv tool sits outside the trusted prefixes, so the wizard offers to trust
its directory instead of skipping it. Proxy connectors are detected but left
out of the observe-all set, because they own the single LLM proxy port and
can't run beside other connectors. The wizard prints a one-line note that
points you to defenseclaw setup <proxy> for them.
An agent version newer than DefenseClaw's tested versions keeps action mode and
is reported as an untested newer version. An action connector whose installed
version has no hook contract (below the tested floor, on the known-broken list,
or an unmatched exact build) is downgraded to observe with a warning, the
same check the gateway applies when it starts. Override it only for exploratory
testing, with DEFENSECLAW_ALLOW_HOOK_CONTRACT_DRIFT=1. See
Version policy.
Scripted init (no prompts)
To skip the wizard, including in a session that is a terminal (CI on a pty,
scripted demos), defenseclaw init has two init-only multi-connector
flags. They don't exist on quickstart:
# Observe every detected hook connector, enforce on codex:
defenseclaw init --non-interactive --yes --observe-all --action-connectors codexFlag (init only) | Effect |
|---|---|
--observe-all | Configure every detected hook connector in observe mode. |
--action-connectors codex,claudecode | Comma-separated connectors to configure in action mode. Works with --observe-all (everything else stays in observe); the named connectors are configured even on their own. |
--non-interactive | Skip every prompt. |
--yes / -y | Accept the default for every prompt. |
--connector <x> | Pre-select a single agent. This single-connector path wins over the multi-connector flags. |
With neither multi-connector flag nor --connector, non-interactive init
keeps the single-connector default: one connector found by discovery, in
observe. An explicit --connector always wins. defenseclaw init --help
lists every option, including the LLM and Cisco AI Defense settings.
Path B: zero prompts (defenseclaw quickstart)
The scripted equivalent. It runs the same setup, never prompts and uses safe
defaults: the observe profile, the local scanner, no LLM judge and no HITL.
Run it
defenseclaw quickstart --connector claudecodeReplace claudecode with the connector name of the agent you use.
quickstart configures one connector. Without --connector, it uses the
single configured or detected connector. If more than one connector is
configured or detected, or the installer's hint disagrees with the detected
connector, it exits and asks you to rerun it with --connector <name>. On an
install that already guards other connectors, quickstart --connector <name>
exits without changes instead of dropping them: use
defenseclaw setup <name> --yes to add an agent beside the others, or
defenseclaw init to change the whole set.
Read the report
Both commands end with the same first-run report:
DefenseClaw First-Run
status=ready connector=claudecode profile=observe
────────────────────────────────────────────────────────
Setup
✓ Config created defaults
✓ Bootstrap ~/.defenseclaw
✓ Skill scanner ~/.local/bin/skill-scanner
✓ MCP scanner ~/.local/bin/mcp-scanner
✓ Guardrail claudecode, mode=observe, fail mode=open
✓ Sidecar started
Readiness
✓ Config file ~/.defenseclaw/config.yaml
✓ Audit database ~/.defenseclaw/audit.db
✓ Device key ~/.defenseclaw/device.key
✓ Skill scanner ~/.local/bin/skill-scanner
✓ MCP scanner ~/.local/bin/mcp-scanner
✓ Connector Claude Code settings found
✓ Sidecar running
- LLM API not configured
- Cisco AI Defense scanner_mode is local
✓ Gateway binary found on PATH
Next
defenseclaw doctor
defenseclaw keys list
Adding another agent later: defenseclaw setup <connector>
After a reboot, agent hooks start the gateway on their next call; after defenseclaw-gateway stop, run: defenseclaw-gateway start
Running coding agents in OpenShell sandboxes: defenseclaw sandbox setupThe first line holds the result: status, the connector (or connectors=N
when several were set up) and the profile. Setup lists what the command
did, Readiness what it checked, and Next up to five commands to run
next. A Gateway API port line appears in Setup when another account on the
machine already uses the default port and this account's gateway gets a
different one. When a connector is in action mode with a closed fail mode,
Next also says how to open it.
If the status isn't ready, the report names what needs attention (a missing
API key, a gateway port in use and so on) and the command to run next.
quickstart exits 0 when the status is ready or partial, 1 when it is
needs_attention, and 2 when it stops before changing anything (for example
when it can't tell which connector you mean). --json-summary prints the same
report as JSON; in CI, check its status field rather than only the exit
code, because a partial setup also exits 0.
Drive the agent
Open Claude Code, or whichever agent you set up. DefenseClaw now receives the lifecycle events and interception points that agent supports. Watch the decisions arrive in the live dashboard:
defenseclaw tuiOr take a snapshot of the latest 200 audit events that you can script:
defenseclaw-gateway audit export --newest --limit 200 | jq .To also write events to a JSONL file as they happen, add a JSONL destination (see Observability → Destinations).
What both paths do
List view for small screens. Use the expand button to open the drawing.
- defenseclaw initasks you questions
- your answers1. Saves your choices
- defenseclaw quickstartuses safe defaults
- defaults1. Saves your choices
- 1. Saves your choicesin config.yaml
- 2. Prepares the data dir
- 2. Prepares the data diraudit DB, policies, scanners
- 3. Connects your agent
- 3. Connects your agenthooks, plugin or proxy
- 4. Starts the gateway
- 4. Starts the gatewaydefenseclaw-gateway
- 5. Checks readiness
- 5. Checks readinessprints the report
All quickstart flags
Prop
Type
When to use which
| Situation | Use |
|---|---|
| First-time setup at a terminal | defenseclaw init |
| You want to be asked questions and shown defaults | defenseclaw init |
| Installer hand-off or unattended provisioning | defenseclaw quickstart --connector <x> |
| CI pipeline (no terminal, deterministic config) | defenseclaw quickstart --connector <x> --yes --json-summary |
| Scripted demo or repeatable test fixture | defenseclaw quickstart --connector <x> --force |
Next
Quickstart
Block your first risky tool call in 5 minutes. Install DefenseClaw, run init, turn on blocking for one agent and watch a test command get blocked.
First guardrail, next steps
After the quickstart block. Pause risky calls for your approval with HITL, see how the block works end to end, and the safe ways to allow something a rule blocks.