Changing connectors
Use defenseclaw setup <connector> to add or reconfigure connector wiring, and setup remove <connector> to retire a connector without deleting audit history.
DefenseClaw connector setup is centered on the connector alias:
defenseclaw setup codex
defenseclaw setup hermes --mode action
defenseclaw setup antigravity --mode observeOn a host that already has connector wiring, the interactive flow asks whether to Add the new connector alongside the existing one or Replace the old wiring. Add is the default, also when you pass --yes. Replace is only for hosts where you intentionally want one connector wired after setup finishes.
The audit DB is connector-agnostic. Adding, reconfiguring, removing, or replacing connector wiring does not delete history; each audit row keeps its own connector attribution.
Add or reconfigure
Run the setup alias for the connector you want:
defenseclaw setup codexChoose Add when you want the existing connector(s) and the new connector protected by the same gateway. The new connector gets its own guardrail.connectors.<name> policy block, and defenseclaw status shows the full active roster.
Use --mode observe or --mode action to set the connector's enforcement posture during setup:
defenseclaw setup codex --mode observe
defenseclaw setup hermes --mode actionRemove a connector
When you no longer want a connector wired, remove it explicitly:
defenseclaw setup remove codexThe gateway restarts and tears down that connector's hooks. Pass --no-restart to restart it later.
DefenseClaw refuses to remove the last connector by default because the gateway would enforce nothing. If that is intentional, pass --force. DefenseClaw stays installed; use defenseclaw uninstall to remove it:
defenseclaw setup remove codex --forceReplace instead of add
Choose Replace in the connector setup prompt when you want setup to tear down the previous connector's agent-side files before wiring the new one. This is useful when a single-user workstation is moving from one agent to another and you do not want both configured at the same time.
Non-interactively, pass --replace. Setup asks before it removes the other connectors; --yes skips the question:
defenseclaw setup claude-code --replace --mode actionOpenClaw and ZeptoClaw are proxy-backed and cannot run next to hook connectors, so their setup refuses while hook connectors are configured. To switch the whole install in one command, pass --replace. Setup lists the hook connectors it removes and asks first (--yes skips the question); the gateway tears down their hooks when it restarts:
defenseclaw setup openclaw --replace --mode actionThe reverse works the same way: when the install guards OpenClaw or ZeptoClaw, a hook connector's setup (for example defenseclaw setup claude-code) refuses and changes nothing, because it would remove the DefenseClaw plugin from OpenClaw. Pass --replace to switch; setup names the proxy connector it removes and asks first unless --yes is given:
defenseclaw setup claude-code --replace --mode actionVerify
defenseclaw doctor
defenseclaw statusdoctor reports residual hook or config issues. status shows every active connector, its enforcement mode, and the shared gateway state.
See also
- Multi-connector - one gateway enforcing several hook connectors
- Quick aliases - connector setup alias reference
- Disabling - roll back agent-side hook entries
- HITL - per-connector approval behavior
Multi-connector
One DefenseClaw gateway enforces guardrail policy for several hook connectors at once, each with its own mode, fail mode, HITL, block message and rule pack under guardrail.connectors. Add a connector with setup <connector> and choose Add.
Disabling guardrail
defenseclaw setup guardrail --disable is the global rollback. Connector hooks are removed or restored from the hash-checked backup, and agents run without DefenseClaw until you turn the guardrail back on.