# Coders Talk

**Category:** 💻 Developer Tools  
**Repository:** https://github.com/coders-talk/coders-talk-plugin  
**Views:** 0  
**Installs:** 0  
**Upvotes:** 0  
**Directory Page:** https://allmcps.com/mcp/coders-talk

## Description
Real coding-agent sessions: what worked, where agents failed and what the human did about it.

## Claude Desktop Quick Installation
Heuristic fallback — verify the package name and runner against the repository README before running it. Uses `npx` (confidence: low):

```json
"mcpServers": {
  "coders-talk": {
    "command": "npx",
    "args": ["-y","coders-talk"]
  }
}
```

## Documentation & README

# Coders Talk for Claude Code and Codex

Send the Claude Code or Codex session you are in to [Coders Talk](https://coders.talk) as a draft Build: the prompts, interventions and fails that mattered, with the raw log one layer down. The plugin never publishes. The draft is private: only you see it, or your team when the session ran in one of the team's repositories. You review every moment on the site and publish it there if you want to.

The other way round, the plugin gives your agent the Coders Talk library: before a non-trivial task, or after a few failed attempts, it can look up sessions where other developers did something similar, and what went wrong for them (see [The library in your agent](#the-library-in-your-agent)). And `/coders-talk:use` puts a published Build's playbook, what that session learned the hard way, into your repository as a skill or a rule (see [Playbooks](#playbooks)).

## Install

### From a terminal

```
curl -fsSL https://coders.talk/install.sh | sh        # macOS and Linux
irm https://coders.talk/install.ps1 | iex              # Windows, in PowerShell
coders-talk login
```

This installs `coders-talk`, one file with no Node.js needed, into `~/.coders-talk/bin` and adds that folder to your PATH (the rc file of your shell; on Windows the user PATH). The installer takes the file for your platform from this repository's [releases](https://github.com/coders-talk/coders-talk-plugin/releases) and checks it against the release's `SHA256SUMS`. No sudo or administrator rights. `CODERS_TALK_VERSION=0.11.0` installs that version, `CODERS_TALK_NO_MODIFY_PATH=1` leaves PATH alone.

`coders-talk login` waits in the terminal until you press Connect in the browser; over SSH it prints the link and the code to open elsewhere. `coders-talk update` replaces the file with the latest release after checking its SHA256. A command you type mentions a newer release in one line, at most once a day; it never waits for the network to do so, and hooks never check. `CODERS_TALK_NO_UPDATE_CHECK=1` turns that off.

Then `coders-talk enable` connects Claude Code and Codex to it. It says what it found and what it will do, asks, and then installs the plugin through each agent's own plugin system: it lays the plugin out in `~/.coders-talk/plugin` and adds that folder as the local marketplace `coders-talk-local` (`claude plugin marketplace add`, `claude plugin install coders-talk@coders-talk-local`; `codex plugin marketplace add`, `codex plugin add`). It is the same plugin as the one below, but its hooks and skills call `coders-talk` by its absolute path, so no Node.js is needed and desktop apps find it without your shell's PATH. On the way it:

- replaces the plugin from the GitHub marketplace (`coders-talk@coders-talk`), whose hooks would otherwise run twice;
- finds a Coders Talk MCP server you added by hand (`claude mcp add`, `mcp_servers` in Codex's `config.toml`) and removes it, or keeps it and installs the plugin without its own server for that agent;
- asks once about auto mode for every agent it found (off unless you say otherwise). Codex runs the hooks only after you trust them in `/hooks`; `enable` does not do that for you;
- in a git repository, asks whether to put the Coders Talk git hooks into it (no, unless they are there already; see [Git hooks](#git-hooks)).

`coders-talk enable --yes` goes ahead without asking, with `--agent=claude-code,codex`, `--auto=off|on|team|push`, `--mcp=remove|keep` and `--git-hooks`, `--no-git-hooks` or `--no-trailers` for the answers. `coders-talk status` shows the file, the sign-in, each agent's Coders Talk plugins and auto mode, and the git hooks of the repository you are in. `coders-talk disable` uninstalls the plugin and its marketplace from both agents and takes the git hooks out of every repository `enable` put them in; the sign-in, your settings and the file stay. `coders-talk update` lays the plugin out again in the new version and updates it in the agents, so the plugin's version is always the file's.

To send a session without going back into it, run `coders-talk sessions` in the folder it ran in: it lists that folder's Claude Code and Codex sessions (also those run at the top of its repository), newest first, with how many prompts each has, the start of the first one and whether it was sent already. `coders-talk build 2` then shows the same summary and privacy check as `/coders-talk:build`, asks `[y/N]` and sends; `coders-talk build` alone takes the newest session, and a session id works too. It takes the same options (`--private`, `--team=<slug>`, `--keep=<numbers>`, `--continues=<link>`). It runs only in a terminal: neither an agent nor a script can answer its question, and there is no `--yes`. From a script, `coders-talk preview <id>` and `coders-talk send <id>` (with `--agent=codex` for Codex) do the two steps.

A Coders Talk connector your organisation added in claude.ai is not visible on your computer, so `enable` cannot find it. If the agent then lists the library's tools twice, turn one of the two servers off in `/mcp`.

### From the agent

1. In Claude Code:

   ```
   /plugin marketplace add coders-talk/coders-talk-plugin
   /plugin install coders-talk@coders-talk
   ```

2. Connect it to your account: `/coders-talk:login`. It opens coders.talk in the browser; check that the page shows the same code as Claude Code and press Connect. The plugin receives its token directly from the site and keeps it in `~/.coders-talk/credentials.json`, readable by you only. There is no token to copy, and it never passes through the chat. The sign-in request names only the program asking (`Claude Code`, `Codex` or `Coders Talk CLI`) and its version, not your computer; the site lists the token under that name in Settings → Agent plugins.

Needs Node.js 20 or newer, nothing else.

#### Codex

```
codex plugin marketplace add coders-talk/coders-talk-plugin
codex plugin add coders-talk@coders-talk
```

Start a new session, then `$coders-talk:login` and `$coders-talk:build` (the same commands as below, with `$` instead of `/`). For the library, also run `codex mcp login coders-talk` once in a terminal. Codex asks to run the plugin's command outside its sandbox: it needs the network to reach coders.talk and your home folder for the sign-in. The session is found through `CODEX_THREAD_ID` in `~/.codex/sessions` (or `CODEX_HOME`), and HEAD at its start comes from the rollout's `session_meta`, so Codex needs no hook for it. Codex runs the plugin's hooks only for auto mode (see Auto mode), and only once you trust them in `/hooks`.

One repository serves both agents: Claude Code reads `.claude-plugin/` and `skills/`, Codex reads `.codex-plugin/`, `.agents/plugins/marketplace.json`, `codex/skills/` and `codex/hooks.json` (its manifest points there, so Codex never picks up `hooks/hooks.json`; the same scripts run with `--agent=codex`). Codex does not expand `${CLAUDE_PLUGIN_ROOT}` or `${CLAUDE_SESSION_ID}` in skills, so its skills give the script path relative to the skill file and pass `--agent=codex`.

## Use

| Command | What it does |
| --- | --- |
| `/coders-talk:build` | Shows what would be sent (project folder, prompts, time span, size), where it goes and what the privacy check found, asks, sends, prints the draft link. |
| `/coders-talk:build --private` | The same, and the draft stays yours even in a team's repository. |
| `/coders-talk:build --team <slug>` | The same, and the draft goes to that team (the part after `/t/` in the team's link). |
| `/coders-talk:auto on` | From now on every session of this agent on this computer is sent by itself while it runs and when it ends (see Auto mode). |
| `/coders-talk:auto team` | The same, only for sessions in repositories of teams that ask for it. |
| `/coders-talk:auto off` | Stops it. `/coders-talk:auto` alone says whether it is on and what it last sent. |
| `/coders-talk:auto session on` | Only this session is sent by itself, even with auto mode off. `session off` keeps this session on the computer whatever the mode; `session` alone says which applies. |
| `/coders-talk:login` | Connects this computer through the browser, or says which account it is connected to. |
| `/coders-talk:logout` | Forgets the token on this computer (revoke it on the site under Settings → Agent plugins). |
| `/coders-talk:lookup <task>` | Searches the Coders Talk library for sessions of a similar task and shows what came back. The agent also does this by itself (see below). |
| `/coders-talk:use <link>` | Shows a published Build's playbook as a skill for this agent: the whole text, where it goes and what changed since the version here. Asks, then writes it. `--as rule` or `--as prompt` for the other two forms; `--team <team> --stack <stack>` for your team's rules (see [Playbooks](#playbooks)). |

Sending the same session again updates its draft until you publish it.

Two rules:

- **Commands that send your session** (`build` and `auto`, and `login` and `logout` with them) run only when you type them. The agent never invokes them on its own.
- **Putting a playbook into your repository** (`use`) runs only when you type it too. The library may tell the agent that a session has a playbook; the agent can only pass that on to you.
- **Searching the library** is something the agent does by itself when a task calls for it (the `lookup` skill and the `coders-talk` MCP server). It sends a short description of the task and the stack, never the session. Switch it off in `/mcp` (Claude Code) or in `~/.codex/config.toml` (Codex); see [The library in your agent](#the-library-in-your-agent).

A forked session (`/branch` or `--fork-session` in Claude Code, a fork in Codex) is sent as its own draft, and the plugin tells the site which session it came from and where it left it. The fork's Build then says it is a fork and links to the Build of the original session, and the original's Build links to its forks. Whichever of the two is sent first, the link appears once both are on the site. Claude Code writes the lines the fork inherited with the original's session id and Codex names it in the rollout's `session_meta`, so no hook is needed for it.

If the privacy check found something the preview lists it by number; it goes as `[REDACTED]` unless you name its number, and the preview runs again with `--keep=<numbers>` (see [What leaves your machine](#what-leaves-your-machine)).

If coders.talk cannot be reached or answers with a server error, the send step opens `coders.talk/new` in the browser and the file manager with the prepared `.jsonl.gz` selected, and prints the link and the path: drop the file on the page. It is the same checked file the preview described. It is kept for 30 minutes, so sending again once the site is back works too; after that the next run of `coders-talk` (or the next session start) deletes it. `CODERS_TALK_NO_BROWSER=1` keeps the browser and the file manager closed; the link and the path are printed anyway. A rejected token or request never ends up there: sign in again instead.

### Auto mode

Off until you turn it on, per computer, per site and per agent: `/coders-talk:auto on` in Claude Code never sends Codex sessions, and `$coders-talk:auto on` in Codex never sends Claude Code ones. With it on, each session is sent the way `/coders-talk:build` would send it, without asking: to your team's space when the repository is one of your team's, else to your private Builds. With `/coders-talk:auto team`, only sessions in repositories of teams that ask for it (a team setting) are sent, and nothing else leaves the machine. A team can ask; it can never switch this on for you.

One session can choose for itself. `/coders-talk:auto session on` sends the current session the way `on` would, even while auto mode is off for the computer; other sessions are not touched. `/coders-talk:auto session off` keeps the current session on the computer whatever the mode, the git hooks' push included (what it already sent stays a draft). The choice is kept in `auto-sessions.json` with the session, so a resumed session keeps it, and `/coders-talk:auto off` does not forget it. `CODERS_TALK_AUTO=0` still stops everything.

Three hooks do the sending, each in a background process so the agent never waits for an upload:

- `Stop`, after an answer of the agent: when the session grew and the last send is ten minutes old, it is sent as still going. The draft stays up to date, and a crash loses at most those minutes. A session shorter than ten minutes is only sent at its end.
- `SessionEnd`: the session is sent once more, as ended. Codex also ends a session after 30 idle minutes, which is what ends one in its desktop app.
- `SessionStart`: sessions that never said they ended (a crash, a closed terminal) and grew since their last send are sent at the next start, up to three at a time. One quiet for half an hour goes as ended; a fresher one as still going. Only sessions auto mode saw while it was on, or turned on for themselves, are considered, never older history.

The site asks the model for moments once per session, when it is over: when the plugin says it ended, or after half an hour without anything new. Sending a session that is still going costs nothing and does not count against the daily limit.

Nothing is published by it. A session you already published is left alone. Every send gets a line in `~/.coders-talk/auto.log`: sent or synced (with the draft link), skipped and why, or failed. The log keeps its last 500 lines, none older than 30 days. `~/.coders-talk/auto-sessions.json` remembers which sessions auto mode saw and how much of each went, never their content; `/coders-talk:auto off` forgets it. `CODERS_TALK_AUTO=0` in the environment turns auto mode off for that shell.

In Codex the hooks are `codex/hooks.json`. Codex runs a plugin's hooks only once you trust them: type `/hooks` and trust the three Coders Talk hooks (`$coders-talk:auto on` reminds you). On Windows Codex runs them through PowerShell and puts the plugin folder into `${PLUGIN_ROOT}` itself. When the Codex CLI exits it also ends what its hooks started, so the session-end hook waits up to three seconds for the upload; what does not make it goes at the next start, and the site asks for moments after half an hour without anything new anyway.

### Private and team drafts

A draft is private: it is in your [My builds](https://coders.talk/library), not in the feed, search engines or your profile. If you are in a team on Coders Talk and the session ran in a repository of one of the GitHub organisations the team named, the draft goes to the team's space instead: the team sees it, nobody else. The preview says where the draft goes before anything is sent; `--private` and `--team <slug>` override it. Publishing to the community is always a separate step on the site, and for a team's draft only if the team allows it.

## The library in your agent

The plugin brings an MCP server, `coders-talk` (`https://coders.talk/mcp`), with three read-only tools: `search_coding_agent_sessions` finds published sessions of a similar task, `get_coding_agent_session` reads one of them, `find_coding_agent_failures` finds where agents failed on a similar problem and what the human did. The `lookup` skill tells the agent when to use them (before a non-trivial task on a known stack, after two or three failed attempts, when you ask how others did something), what may go into a query and what may not, and to treat the answers as other people's experience: it never runs a command from them without asking you. When a session helped, it says so with the link.

- **Signing in.** In Claude Code the server uses the sign-in of `/coders-talk:login`: `.mcp.json` asks `scripts/coders-talk.mjs mcp-headers` for the token at each connection (`headersHelper`), so the token is in no config file and never passes through the chat. Not signed in, the server asks you to sign in through the browser in `/mcp`. Codex runs a plugin's header helper from the session's folder with an empty environment, where the plugin cannot find its own script, so in Codex the server signs in on its own: run `codex mcp login coders-talk` once. Both need access to the library: during the closed beta, see [coders.talk/for-agents](https://coders.talk/for-agents).
- **What a search sends.** The query (a few words about the task, or the symptom of a failure), the stack, and the agent's name. The agent is told never to put code, paths, repository, company or client names, hostnames, URLs or secrets in it. The site keeps the query text, the filters and how many results it found for 180 days, not tied to you or your IP address. The session itself never goes with it.
- **Switching it off.** Claude Code: `/mcp`, choose `coders-talk`, disable. Codex: in `~/.codex/config.toml`

  ```toml
  [plugins."coders-talk@coders-talk".mcp_servers.coders-talk]
  enabled = false
  ```

- **Another site.** The plugin's server always points at `https://coders.talk/mcp`: the Claude desktop app compares the address it shows with the session's and does not expand variables, so a `${…}` address breaks signing in there. For another site add your own server and switch the plugin's off: in Claude Code `claude mcp add --transport http coders-talk-dev http://…/mcp`, in Codex `[mcp_servers.coders-talk-dev]` with `url = "http://…/mcp"` in `config.toml`. Sending sessions still follows `CODERS_TALK_URL` and the plugin option `url`.
- **Which Builds your session used.** When you send a session, the plugin counts the agent's calls to these tools in it and collects the Builds their answers linked to (`/b/<slug>?ref=agent`), up to 20, and the Builds whose playbooks the agent worked with: a `ct-<slug>` skill it ran (the Skill tool, or `/ct-…` typed in Claude Code; a `<skill>` block, or the agent reading the skill's `SKILL.md`, in Codex), by the Build's link at the end of the skill's text. A playbook written as a rule into `AGENTS.md` or `CLAUDE.md` is in every session whether it helped or not, so it is not counted. The preview shows them. The site links your draft to those Builds: "Used from the library" and "Built with the playbook from @author" on yours, "Helped N published sessions" and "N built with its playbook" on theirs, once yours is published. Only the count and the slugs are sent, not the queries: in the session itself each library call goes as the tool's name with `[library call — not kept]` in place of the query and of the answer. The count and the slugs are taken from the session file on your computer before that.
- **A suggestion to share.** Once per session, after an answer, when the agent got Builds from the library and the session changed code, the `Stop` hook shows you one line: "Your agent used 2 Builds from coders.talk in this session. Share yours: /coders-talk:build". It sends nothing, and it never shows with auto mode on. To read the session for it, the hook goes on from where it stopped the last time and keeps that place, the count and the slugs in `~/.coders-talk/nudges/`. Turn it off with `CODERS_TALK_NUDGE=0`, or `node <plugin folder>/scripts/coders-talk.mjs nudge off`. In Codex the hook runs only once you trust the plugin's hooks in `/hooks`.

### Playbooks

A published Build can come with a playbook: what its session taught, written for an agent from the Build's page (when to use it, the approach, the pitfalls, the checks, and a better first prompt). `/coders-talk:use <link or slug>` (`$coders-talk:use` in Codex, `coders-talk use` in a terminal) shows it in full, says where it would go and what changed since the version already here, and writes it only after you say yes.

| `--as` | Claude Code | Codex |
| --- | --- | --- |
| `skill` (the default) | `.claude/skills/ct-<slug>/SKILL.md` | `.agents/skills/ct-<slug>/SKILL.md` |
| `rule` | a block in `CLAUDE.md` | a block in `AGENTS.md` |
| `prompt` | shown, not written | shown, not written |

- The paths are at the root of the repository you are in, or in the folder itself outside a repository. A skill is a folder of its own: delete the folder and it is gone. The agent opens it by itself when a task matches its description; its front matter has a name and a description and nothing else, so no tool permissions.
- A rule is the block between `<!-- coders-talk:<slug>@<version> -->` and `<!-- /coders-talk:<slug> -->`; the rest of the file stays as it was, line endings included. When `CLAUDE.md` imports `@AGENTS.md`, the block goes into `AGENTS.md` once and both agents read it. With both files and no import, it goes into the file of the agent you chose, and the output says the other agent will not see it.
- `.coders-talk/uses.json` in the repository notes what was written: the Build, the version, the format and the agent. Nothing updates by itself: `use` again shows what changed and asks again.
- In a terminal it asks `[y/N]` before writing, and asks for which agent when both are on this computer. For scripts, `--agent=claude|codex` and `--write` answer both.
- It asks the site for one public file, `/b/<slug>/use/<format>.md`, with `via=cli` and the agent; the request that goes with writing adds `write=1`, which the site counts as a use (once a day). Nothing about your repository goes with it, and no token: only when the file is not public (a Build of your team that is not published) does it ask again with your sign-in, and only this site ever gets it. A team's own Build is not counted.
- Your team's rules: `use --team=<team> --stack=<stack>`, as the team's page shows it. The rules the team merged for that stack, in one block in `CLAUDE.md` or `AGENTS.md` (`<!-- coders-talk:team-<team>-<stack>@<version> -->`), written the same way as a rule. A rule changes only when the team merges a proposal on the site, so every member gets the same block. For members only, so it needs the sign-in. When the block here is older, `use --team` names the proposals merged since.
- Kept up with: at the start of a session in a repository with a team's block, the `SessionStart` hook says in one line when the team merged a proposal since the block was written, from what the last check found. It never goes to the network itself: when the last check is over six hours old it starts one in the background (`GET /t/<team>/rules/<stack>.md` with `If-None-Match` and your sign-in; the site answers 304 until a merge), and notes the result in `~/.coders-talk/team-rules.json`. It never rewrites the block: `use --team` does, when you run it.
- Once written, it prints the Build's link with `?ref=use`: open it after your agent has worked with the playbook and say whether it worked for you.

### Git hooks

Only in a repository where you said yes to `coders-talk enable` (or `--git-hooks`); never globally. Two hooks, each a block between `# >>> coders-talk` and `# <<< coders-talk` right after the first line, so a hook already there keeps its own lines and `disable` leaves it as it was:

- `prepare-commit-msg` adds `Agent-Session: <session id>` to a commit that holds a session's work: a Claude Code session whose answers changed a staged file that has not been committed since (the git snapshots tell), or a Codex session that auto mode follows in this repository and that was written to since the last commit. Merges and squashes are left alone, and the same trailer is never added twice. `--no-trailers` leaves this hook out. The session id becomes part of the repository's history: in a public repository everyone sees it.
- `pre-push` finds the sessions behind the commits you push, by their trailers and by the Claude Code snapshots that saw those commits. With auto mode `on`, `team` or `push`, it sends them in the background, as ended. Without auto mode, it prints one line saying how many sessions are behind the push. The push never waits for the network and never fails because of Coders Talk, and the snapshot refs (`refs/coders-talk/…`) are never pushed.

Auto mode `push` sends a session only when its commits are pushed; sessions whose code you never push stay on your computer. The agents' own hooks send nothing in this mode.

A repository whose hooks live elsewhere (`core.hooksPath`: husky, lefthook, a shared folder) gets no hooks from `enable`: it prints the lines to add to those hooks yourself.

## What leaves your machine

- By default, only the session you run `/coders-talk:build` in, and only after you confirm.
- With [auto mode](#auto-mode) on, which only you can switch on, each session of that agent on this computer, without asking (with `team`, only sessions in repositories of teams that ask for it; with `push`, only sessions whose commits you push). Nothing is published either way.
- With the [git hooks](#git-hooks) in a repository, the session id goes into your commits as an `Agent-Session` trailer, so it leaves with every push of those commits, to wherever you push them. The session itself does not.
- The session `.jsonl` without screenshots, thinking blocks and the agent's bookkeeping lines, with tool output cut to 60 lines, gzipped. Calls to the Coders Talk library go by the tool's name only, without the query and the answer. The plugin's own run is cut off the end. Big files are read line by line: a 417 MB Codex rollout full of screenshots goes as about 200 KB.
- If the session ran in a git repository: the `origin` address when it is on GitHub, the branch, and the titles, hashes and size (files, +/−) of the commits the session made (the site links each commit on GitHub; the commits themselves are not sent). The address of a private repository is shown only to the draft's own audience (you, or your team) and is removed when the Build is published. In Claude Code a `SessionStart` hook remembers `HEAD` at the start of each session in `~/.coders-talk/sessions/` for this; it sends nothing and prints nothing.
- The files that changed, as diffs (up to 300 lines a file; env, key and credential files, lock files and builds by name only). The env and credential files the plugin knows by their names: `.env` and `.env.*` (not `.example`, `.sample`, `.dist`, `.template`), `*.env`, `.envrc`, `.dev.vars`, `.npmrc`, `.netrc`, `.pypirc`, `.pgpass`, `auth.json`, `credentials*`, `.git-credentials`, `id_rsa` and the other SSH keys, anything under `.ssh/`, `*.pem`, `*.key`, `*.p12`, `*.pfx`, `*.jks`, `*.keystore`, `kubeconfig`, `.kube/config`, `.docker/config.json`, `secrets.yml`/`.yaml`/`.json`/`.toml`, `*.tfvars`, `*.tfstate`, `*.tfstate.backup`, `.terraformrc`, `.htpasswd`, `application_default_credentials.json`, `local.settings.json`, `.vault-token`, `.s3cfg`, `.boto`, `*.kdbx`, `*.gpg`, `*.ovpn`. For those the session keeps no content either: a tool call that reads, searches or edits one (`Read`, `Grep`, a `Bash` or `PowerShell` command that names it; in Codex a patch or a command that names it) goes with its output replaced by `[content not shown, the file may hold secrets]`, and in Codex its input too. A file with another name is not recognised, so check the preview. In Claude Code `scripts/snapshot.mjs` runs on `SessionStart`, `UserPromptSubmit` and `Stop` and takes a git snapshot of the working tree: a temporary index in `~/.coders-talk/snapshots/`, tracked changes and new files up to 1 MB, a tree chained under `refs/coders-talk/<session>`. Your branch, index and files are not touched, and a plain `git push` does not send that ref. The build step turns neighbouring snapshots into what the agent changed in each turn (Bash and subagents included), what you changed by hand between its answers, and the commits of each turn. A snapshot slower than 3 seconds turns them off for the session. Snapshots and their refs older than 14 days are removed at the next session start in the same repository, and whenever `coders-talk build`, `coders-talk status` or the pre-push hook runs there (see [What the plugin writes into a repository](#what-the-plugin-writes-into-a-repository)). Without git, or in Codex, the diffs come from the agent’s own edits in the session.
- Secrets the privacy check recognises: keys, tokens, connection strings, passwords in URLs, email addresses, public IP addresses and internal hostnames that match its rules are replaced with `[REDACTED:TYPE]` on this computer, before anything is sent, in the session, the branch name and the commit titles alike. A check by patterns misses what it does not recognise (a password in plain words, a token of an unusual format, a client's name you did not list), and that goes as it is: read the preview, and the draft on the site before you publish it. A home folder in a path (`C:\Users\you`, `/Users/you`, `/home/you`) becomes `~`. The preview lists each finding by number and kind, never its value; `--keep=<numbers>` sends one as it is, and only a SHA-256 of it goes to the site, so the site's own second check leaves it alone. Kept values are remembered as hashes in `~/.coders-talk/kept.json`. Words to hide in every session, such as client names or internal services, go in `~/.coders-talk/privacy.json` as `{"redact": ["Globex", "billing-core"]}`. The rules are the site's own (`scripts/lib/privacy.mjs`, generated from coders.talk), checked against the same cases in `test/fixtures/privacy`.
- The number of tokens the session spent per model (input, output, cache reads and writes), counted from the session file before it is slimmed. Only the counts; they show on the Build and in your team's numbers.
- For a forked session, the id of the session it was forked from and the time of the fork, so the site can link the two Builds.
- If the agent used the Coders Talk library in the session: how many times it called it, and the slugs of the Builds it got (up to 20).
- Apart from sessions: the library searches the agent makes by itself (a short task description and the stack; see [The library in your agent](#the-library-in-your-agent)), and `use`, which only fetches a public playbook ([Playbooks](#playbooks)).
- The token can start imports and read the library. Revoke it in Settings at any time.

Each network call, and what goes with it:

| Call | When | What goes |
| --- | --- | --- |
| `POST /api/v1/device/codes`, `/device/token` | `login` | The program's name (`Claude Code`, `Codex` or `Coders Talk CLI`) and version; then the device code. No token, no computer name. |
| `GET /api/v1/me` | `whoami`, `auto`, the preview (to say where the draft goes) | The token. |
| `POST /api/v1/imports`, `GET /api/v1/imports/{id}` | `build`/`send` after your yes; auto mode | The slimmed, checked session; `agent`, `session_id`, `client_version`, `trigger`; the git context (GitHub `origin`, branch, commit titles, hashes and sizes); token counts; the privacy summary (counts by type, hashes of kept values); `space`, `continues`, `fork`, `library` (count and up to 20 slugs). The token. |
| `/mcp` | the agent searches the library | The query and the stack the agent writes, and the token. Never the session. |
| `GET /b/<slug>/use/<format>.md`, `/t/<team>/rules/<stack>.md` | `use` | `via=cli`, the agent, `write=1` when it writes. The token only for a team's own Build or rules. |
| `GET /t/<team>/rules/<stack>.md`, `/t/<team>/rules/<stack>.json?since=<version>` | `SessionStart` (in the background, at most every six hours), `use --team` | `via=hook`, `If-None-Match` with the version in the repository, the token. Only for repositories with a team's block. |
| GitHub Releases | `update`, and a background check at most once a day from a terminal | The request for the release, with `coders-talk/<version>` as its user agent; nothing about you or your sessions. |

## What the plugin keeps on your computer

`~/.coders-talk` (or `CODERS_TALK_HOME`) is readable by you only: the folder and every folder in it 0700, every file 0600 (Windows keeps the user profile private instead).

| File | What | Kept |
| --- | --- | --- |
| `credentials.json`, `login-pending.json` | The token per site; a sign-in waiting for Connect | Until `logout`; until the sign-in ends |
| `auto.json`, `auto-sessions.json`, `auto.log` | Auto mode's choice, the sessions it saw (path, sizes, times), what it sent | Until you change it; each session 14 days after it was last seen; 500 lines, none older than 30 days |
| `sent.json` | Sessions you sent by hand, with the draft link | 90 days |
| `sessions/<id>.json` | Where a Claude Code session ran and `HEAD` at its start | 30 days |
| `snapshots/<id>.json`, `.index` | The git snapshots of a Claude Code session | 14 days |
| `nudges/` | Where the Stop hook stopped reading, and the counts and slugs it found | 14 days |
| `kept.json`, `privacy.json` | Hashes of values you chose to send; your words to hide | Until you edit them |
| `enable.json`, `plugin/`, `update.json`, `nudge.json` | `enable`'s answers, the plugin it lays out, the update check, the suggestion switch | Until `disable` or the next `enable`/`update` |

The preview writes `<temp folder>/coders-talk/<session>.jsonl.gz` and `.json` (a private folder, private files): deleted after a send, when you say no (`build`, or the `discard` step of the agent's build skill), and otherwise 30 minutes after the preview, by the next run of `coders-talk` or the next session start.

## What the plugin writes into a repository

- **Git hooks and the `Agent-Session` trailer**: only with `coders-talk enable --git-hooks` (or a yes to `enable`'s question) in that repository. `.git/hooks/prepare-commit-msg` and `pre-push` get a block between `# >>> coders-talk` and `# <<< coders-talk`; the trailer goes into the commits you make from then on. `disable` takes the blocks out; trailers already in commits stay in history.
- **Snapshot refs** (Claude Code): `refs/coders-talk/<session>` in the repository's `.git`, one per session, pointing at snapshot commits made from temporary indexes. Never pushed by a plain `git push`. The refs go after 14 days (see above); their objects stay in `.git` until your own `git gc` prunes them, which the plugin never runs.
- **`use --write`**: the skill (`.claude/skills/ct-<slug>/SKILL.md` or `.agents/skills/ct-<slug>/SKILL.md`) or the rule block in `CLAUDE.md`/`AGENTS.md`, and `.coders-talk/uses.json`: one entry per Build, format, agent and path, with the Build's slug, the version (`hash`), the format (`skill` or `rule`), the agent (`claude` or `codex`), the path written, the time (`at`), and for a team's rules the team and the stack. Nothing else: no user name, no token. Commit it or add it to `.gitignore`, as you like.

## Configuration

| Setting | Where | Default |
| --- | --- | --- |
| Site address | `CODERS_TALK_URL`, or in Claude Code the plugin option `url` (asked when the plugin is enabled). In Codex set the variable in `~/.codex/config.toml`: `[shell_environment_policy]` `set = { CODERS_TALK_URL = "https://…" }` | `https://coders.talk` |
| Token | `/coders-talk:login` saves one per site; `CODERS_TALK_TOKEN` overrides it (for CI, or a token made in Settings by hand) | none |
| Data folder | `CODERS_TALK_HOME` | `~/.coders-talk` |
| Suggestion to share a session that used the library | `CODERS_TALK_NUDGE=0` turns it off for a shell; `coders-talk.mjs nudge off` for this computer | on |
| Proxy | `HTTPS_PROXY` (`HTTP_PROXY` for an `http://` site, `ALL_PROXY` for both), `NO_PROXY` for hosts that go direct. Lower-case names work too. An `http://` or `https://` proxy, with `user:password@` if it asks; a `socks://` one is ignored. In Codex, if a variable does not reach the plugin, add it to `set` as above | none: direct |

Node's own `fetch` ignores the proxy variables, so the plugin opens the proxy's `CONNECT` tunnel itself. Some networks reset a direct connection to the site after the first 16 KB, which lets `whoami` through but not an upload; there the proxy is what gets a session out.

The script reads the `url` option from Claude Code's own `settings.json` (`pluginConfigs`). It does not rely on `${user_config.url}` in the skills or on `CLAUDE_PLUGIN_OPTION_*` variables: in testing, the desktop app left the placeholder unexpanded and the variable did not reach commands the model runs.

## Development

```
npm test                              # node --test, no dependencies
claude plugin validate . --strict
claude --plugin-dir .                 # try it in a real session
npm run build                         # dist/coders-talk-<platform>-<arch>, needs Bun
npm run test:binary                   # the command and hook tests again, on that file
```

The single file is the same scripts compiled with `bun build --compile` (`scripts/build.mjs`): `coders-talk.mjs` is its entry, and the hooks run as `coders-talk hook <claude-code|codex> <session-start|prompt|stop|session-end>` (`scripts/lib/hooks.mjs`; the scripts in `hooks/hooks.json` call the same code). The plugin `enable` lays out is made from this repository's skills and manifests, built into the file (`scripts/lib/plugin.mjs`): Claude Code's hooks in exec form (`command` and `args`, no shell), Codex's hooks and skills for PowerShell on Windows (`& '…'`) and sh elsewhere, the MCP `headersHelper` for `cmd.exe` on Windows. `node scripts/build.mjs all` builds every platform: Linux x64 and arm64, macOS x64 and arm64, Windows x64. The file does not read `.env` or `bunfig.toml` from the folder it runs in. A tag `coders-talk--vX.Y.Z` builds, tests and signs the files on each platform and publishes them with `SHA256SUMS` as a release (`.github/workflows/release.yml`).

`scripts/lib/slim.mjs`, `scripts/lib/usage.mjs` and `test/fixtures/slim` are generated from the site repository (`resources/js/lib/slimSession.ts`, `resources/js/lib/sessionUsage.ts`), so the plugin trims sessions and counts tokens exactly like the site's upload page does. Change them there, then run `npm run plugin:sync` in the site repository.

API used: `POST /api/v1/device/codes` and `POST /api/v1/device/token` (browser sign-in, no token needed), `POST /api/v1/imports` (multipart: `file`, `agent`, `session_id`, `client_version`, optional `git` (with `commits.shas` next to `commits.subjects`), `usage`, `privacy` (what the local check redacted, by type, and SHA-256 hashes of the values kept on purpose, never a value), `continues`, `fork` (`{"session_id", "at"}`: the session this one was forked from, and when; lines up to `at` are the original's), `library` (`{"calls", "slugs"}`: how often the agent called the library, and up to 20 slugs of the Builds it got; unknown slugs are dropped), `trigger` (`manual` or `auto`) and `space`: `personal` or a team slug; the response says where the draft went in `space`, the original's Build in `forked_from` (`{slug, title, url}`, or null while it is not on the site), and an automatic send of a session already published answers `{"status": "skipped"}`), `GET /api/v1/imports/{id}`, `GET /api/v1/me` (the account and its teams with their GitHub owners and whether each asks for automatic sending), with `Authorization: Bearer <token>`. The MCP server is `/mcp` (Streamable HTTP, the same token; `mcp-headers` prints it for Claude Code). Errors come as `{"error": {"code", "message"}}`.

