Integrations
Use the Watcher client for its built-in agent connections. Use gateway hooks or the Python SDK to connect other tools. SDK examples show how to make those connections and state the limits of each one.
Built-in connections
| Connection | Recording | Tool blocking | Setup |
|---|---|---|---|
| Local Claude Code | The client records sessions through agent hooks. | Blocking review runs before covered tool calls. | Supported agents |
| Local Codex | The client records sessions through agent hooks. | Watcher reviews requests that Codex routes through its approval flow. | Supported agents |
Blocking review depends on the agent's execution path and settings. Watcher cannot block tools in a Codex run that requests no approvals. Recording alone does not mean a tool was checked before it ran.
Claude Tag monitoring is unsupported. See Supported agents for its limits.
SDK examples
The examples are source code to adapt and test in your own environment. Example in the support column is distinct from a built-in client connection.
Download watcher_sdk-<version>-source.tar.gz from the
Watcher release matching your server.
Extract it with tar -xzf watcher_sdk-<version>-source.tar.gz, replacing
<version> with the release number without its leading v. The examples are
under sdk/examples/. Keep the whole sdk/ directory together: Python examples
install the SDK from the adjacent source. The wheel installs the client library and optional CLI; adapters ship in the
source archive. Older source releases may not contain examples.
The integration links below lead to upstream projects or their documentation.
Source folders refer to paths within sdk/examples/; each folder's README gives
setup, usage, supported inputs, error behavior and test commands.
Set up Copilot
Follow the Copilot quickstart to install recording and blocking review for every Copilot session of your user with one command. The installer provides Python, uv and the adapter. It signs in with your login, through the browser or a saved login, and does not accept API keys. The local Watcher app and a source checkout are optional.
The install is Blocking review by default, or Record only with
--record-only. Your administrator's enforce, observe or paused
enforcement mode
decides what Blocking review does. In enforce mode, a Watcher approval skips
Copilot's own permission prompt and overrides your Copilot deny rules. These
personal hooks are per user and removable; only managed policy hooks, which an
administrator deploys as root, for example through MDM, are enforced by Copilot.
Add --project to install in one project instead. When both installs cover a
project, both run, and install and status warn about it. Opt a project out with
watcher-sdk integrations opt-out copilot --project PATH. Status reports
confirmed transcript delivery separately from the read-back of stored
judgments.
Copilot appears as GitHub Copilot CLI in session views and new alerts. Other recognized SDK agents also appear by name. Agent filters use those names, including for older sessions with retained adapter IDs. A name does not imply support for every feature; the coverage and limits below still apply.
Verification labels
The mode columns summarize recorded tests. Dates identify those runs; they do not establish compatibility with changes made since the test. Read the example's README for the tested environment, covered paths and limits.
| Label | Meaning |
|---|---|
| Static Tests | Adapter tests with simulated Watcher responses; some also exercise installed upstream software. |
| End-to-end testing | The integration path was tested against the Watcher API and database, locally or deployed. Model output or hosted services may use fixtures; see the example's README. |
| Not available | The example does not provide this feature. |
These labels describe test coverage, not a guarantee about all tools or sessions. Read the example's limits before using it for blocking review. Some hooks can refuse a tool without recording a decision. Others may let tools run when a hook does not start, times out, or is not loaded.
Local exporter tests do not establish that a hosted destination indexed the records or generated an alert. Each example README names the tested receiver and the steps needed to verify your destination.
Coding agents
| Integration | Source folder | Observe | Block tools | Last tested | Support |
|---|---|---|---|---|---|
| Aider | aider/ | End-to-end testing | End-to-end testing | 2026-09-26 | Example |
| Amp | amp/ | Static Tests | Not available | 2026-09-26 | Example |
| Cline | cline/ | End-to-end testing | End-to-end testing | 2026-09-26 | Example |
| Continue CLI | continue/ | Static Tests | Not available | 2026-09-26 | Example |
| Cursor | cursor/ | Static Tests | Static Tests | 2026-09-26 | Example |
| Gemini CLI | gemini-cli/ | End-to-end testing | End-to-end testing | 2026-09-26 | Example |
| GitHub Copilot CLI | github-copilot-cli/ | Static Tests | Static Tests | 2026-10-02 | Example |
| Goose | goose/ | End-to-end testing | End-to-end testing | 2026-09-26 | Example |
| Kilo Code | kilocode/ | End-to-end testing | End-to-end testing | 2026-09-26 | Example |
| Mistral Vibe | mistral-vibe/ | End-to-end testing | End-to-end testing | 2026-09-26 | Example |
| OpenCode | opencode/ | End-to-end testing | End-to-end testing | 2026-09-26 | Example |
| OpenHands | openhands/ | End-to-end testing | End-to-end testing | 2026-09-26 | Example |
| Pi | pi/ | End-to-end testing | End-to-end testing | 2026-09-26 | Example |
| Qwen Code | qwen-code/ | End-to-end testing | End-to-end testing | 2026-09-26 | Example |
| Roo Code | roo-code/ | Static Tests | Not available | 2026-09-26 | Example |
| Windsurf | windsurf/ | Static Tests | Static Tests | 2026-09-26 | Example |
General-purpose agents
| Integration | Source folder | Observe | Block tools | Last tested | Support |
|---|---|---|---|---|---|
| OpenClaw | openclaw/ | End-to-end testing | End-to-end testing | 2026-09-26 | Example |
Agent frameworks
| Integration | Source folder | Observe | Block tools | Last tested | Support |
|---|---|---|---|---|---|
| Agno | agno/ | Static Tests | Static Tests | 2026-09-26 | Example |
| AutoGen | autogen/ | Static Tests | Static Tests | 2026-09-26 | Example |
| CAMEL | camel/ | Static Tests | Static Tests | 2026-09-26 | Example |
| CrewAI | crewai/ | Static Tests | Static Tests | 2026-09-26 | Example |
| DSPy | dspy/ | Static Tests | Static Tests | 2026-09-26 | Example |
| Google ADK | google-adk/ | Static Tests | Static Tests | 2026-09-26 | Example |
| Haystack | haystack/ | Static Tests | Static Tests | 2026-09-26 | Example |
| LangChain | langchain/ | Static Tests | Static Tests | 2026-09-26 | Example |
| LangChain4j | langchain4j/ | End-to-end testing | End-to-end testing | 2026-09-26 | Example |
| LangGraph | langgraph/ | Static Tests | Static Tests | 2026-09-26 | Example |
| LlamaIndex | llamaindex/ | Static Tests | Static Tests | 2026-09-26 | Example |
| Mastra | mastra/ | End-to-end testing | End-to-end testing | 2026-09-26 | Example |
| OpenAI Agents | openai-agents/ | Static Tests | Static Tests | 2026-09-26 | Example |
| Pydantic AI | pydantic-ai/ | Static Tests | Static Tests | 2026-09-26 | Example |
| Semantic Kernel | semantic-kernel/ | Static Tests | Static Tests | 2026-09-26 | Example |
| smolagents | smolagents/ | Static Tests | Static Tests | 2026-09-26 | Example |
| Strands Agents | strands/ | Static Tests | Static Tests | 2026-09-26 | Example |
| Vercel AI SDK | vercel-ai/ | End-to-end testing | End-to-end testing | 2026-09-26 | Example |
Gateways
| Integration | Source folder | Observe | Block tools | Last tested | Support |
|---|---|---|---|---|---|
| Bifrost | bifrost/ | End-to-end testing | End-to-end testing | 2026-09-26 | Example |
| Cloudflare AI Gateway | cloudflare-ai/ | Static Tests | Not available | 2026-09-26 | Example |
| Helicone | helicone/ | End-to-end testing | Not available | 2026-09-26 | Example |
| Kong AI Proxy | kong-ai/ | End-to-end testing | End-to-end testing | 2026-09-26 | Example |
| LiteLLM proxy | litellm/ | End-to-end testing | End-to-end testing | 2026-10-01 | Example |
| OpenRouter | openrouter/ | Static Tests | Not available | 2026-09-26 | Example |
| Portkey | portkey/ | End-to-end testing | End-to-end testing | 2026-09-26 | Example |
Model libraries
| Integration | Source folder | Observe | Block tools | Last tested | Support |
|---|---|---|---|---|---|
| Anthropic Messages | anthropic/ | Static Tests | Static Tests | 2026-09-26 | Example |
| Cohere V2 | cohere/ | End-to-end testing | End-to-end testing | 2026-09-26 | Example |
| Google Gen AI | google-genai/ | Static Tests | Static Tests | 2026-09-26 | Example |
| Groq | groq/ | Static Tests | Static Tests | 2026-09-26 | Example |
| Hugging Face Inference | huggingface-inference/ | Static Tests | Static Tests | 2026-09-26 | Example |
| Mistral AI | mistralai/ | Static Tests | Static Tests | 2026-09-26 | Example |
| Ollama | ollama/ | Static Tests | Static Tests | 2026-09-26 | Example |
| OpenAI Responses and Chat Completions | openai/ | Static Tests | Static Tests | 2026-09-26 | Example |
Compliance APIs
| Integration | Source folder | Observe | Block tools | Last tested | Support |
|---|---|---|---|---|---|
| Claude Compliance API | claude-compliance/ | Static Tests | Not available | 2026-09-26 | Example |
Observability and SIEM
| Integration | Source folder | Export | Last tested | Support |
|---|---|---|---|---|
| Google Security Operations | google-security-operations/ | Static Tests | 2026-09-26 | Example |
| Microsoft Sentinel | microsoft-sentinel/ | Static Tests | 2026-09-26 | Example |
| OpenTelemetry | opentelemetry/ | Static Tests | 2026-09-26 | Example |
| Splunk | splunk/ | Static Tests | 2026-09-26 | Example |
Export destinations
Use these examples to send stored decisions, selected session summaries and optional transcripts to an observability or SIEM destination. Open the source folder in your SDK checkout and follow its README. The OpenTelemetry example has a separate setup section for each destination.
| Destination | Source folder | Transport |
|---|---|---|
| Grafana / Loki | opentelemetry/ | OTLP logs through a Collector |
| Datadog | opentelemetry/ | OTLP logs through a Collector |
| Splunk | splunk/ | HTTP Event Collector |
| Microsoft Sentinel | microsoft-sentinel/ | Azure Monitor Logs Ingestion into a custom table |
| Elastic Cloud | opentelemetry/ | Managed OTLP endpoint through a Collector |
| New Relic | opentelemetry/ | OTLP logs through a Collector |
| Dynatrace | opentelemetry/ | OTLP logs through a Collector |
| AWS CloudWatch Logs | opentelemetry/ | OTLP logs signed by the Collector |
| OpenSearch | opentelemetry/ | OTLP through OpenSearch Ingestion or Data Prepper |
| Google Security Operations | google-security-operations/ | Chronicle v1 structured-event import |
An accepted request does not prove searchable records or an alert. The README provides a destination check and states which local tests were run. Reconcile late-arriving records and later decision changes before relying on scheduled exports; occurrence-time windows do not provide a complete change feed.
Choose the data flow
Coding agents and general-purpose agents connect through native tool hooks or approval interfaces. Framework examples use the framework's scheduler or callbacks. A hook can stop a tool only when the host waits for the decision before dispatch. Read the example's timeout behavior and supported tool paths.
For unattended operation, a call that requires a human must remain withheld. Examples with a human approval callback can pass that decision to an authorized interface and record the choice. A local callback is not a built-in approval UI; each README states what the example implements.
Gateway examples install monitoring on the gateway server. Clients using a covered route need no Watcher library. Synchronous plugins can hold a model's tool proposals before the client receives them. Export-only connections import completed requests and cannot stop those requests. A gateway cannot prevent action outside its covered routes or tools that already ran at the provider.
The gateway hook accepts complete provider request/response
pairs or converted transcripts. Its configured
enforcement mode
controls observation, enforcement and paused behavior through the same endpoint.
A successful submission does not prove durable recording. Verify the stored
conversation and decisions through the query API or
Analyzer. Each gateway example starts every
conversation ID it sends with its own prefix, such as litellm:, so its
sessions show the Gateway source there. The LiteLLM example sends an ID only
when the client sets an x-watcher-session-id header. Without that header, its
sessions show Hooks API, as does a custom integration that sends other IDs.
Compliance API ingestion imports activity that has already happened. It supports later review and cannot stop past tool calls.
Observability exports send stored decisions, selected session summaries and optional transcripts to other systems. Transcript content is excluded unless explicitly enabled. The public SDK does not expose a notification-delivery feed; these examples export records, not notification events. Bounded query windows are not a lossless stream of later changes.