Across preserves the context, decisions, checkpoints, code history, and verification behind engineering work so developers and coding agents can reliably understand, review, restore, and continue it.
- Status
- What Across Is
- Quickstart
- Core Concepts
- Commands
- Architecture
- Security Model
- Agent Compatibility
- Development
- Limitations
- License
| Version | 0.0.1 source snapshot (unreleased) |
| Status | Local Alpha |
| Runtime | Local-first; one core CLI binary plus optional protocol-shell adapter binaries |
| Database | SQLite (WAL, foreign keys, migrations) |
| Platforms | macOS (qualified) · Linux (CI-tested) · Windows (compile-checked only, untested) |
| License | MIT |
This is not production-ready. See Limitations for what is unverified.
Across connects developers, coding agents, and git repositories into one evidence-backed local system. Its primary purpose is continuity: stop work today, return weeks later, and answer:
- What was I trying to do?
- What did the agent do? What failed? What succeeded?
- Why was this decision made? Which commit belongs to which session?
- Which tests actually ran? Can I restore the exact code state safely?
Across is not a coding agent, IDE, task orchestration system, replacement for Git/GitHub, vector database, chat-history viewer, LLM wrapper, or note-taking app.
GrayCodeAI also builds Rover. The boundary is explicit:
| Rover owns | Across owns |
|---|---|
| task execution | engineering history |
| agent orchestration | session capture and checkpoints |
| verification execution | commit/session linkage and provenance |
| delivery | context retrieval and handoffs |
Checkpoints belong to Across. Rover may request, consume, and restore them — but does not own them.
# Build
make build
# Configure
export ACROSS_HOME=~/.local/share/across
# Register a repository
./bin/across repo add /path/to/repo
# → repo_abc123
# Start a session
./bin/across session start --repo repo_abc123 --agent codex
# → sess_xyz789
# Install the post-commit hook (auto-checkpoint)
./bin/across hook install /path/to/repo
# Work, commit — a checkpoint is created automatically
# ... git commit ...
# Later: reconstruct context
./bin/across brief "continue auth migration" --repo repo_abc123
# Restore code state safely (new worktree — never resets your checkout)
./bin/across checkpoint restore cp_def456Across distinguishes kinds of knowledge. Never merge these:
| Kind | Meaning | Example |
|---|---|---|
OBSERVED |
Directly verified | Commit abc123 exists |
STATED |
Agent or user claimed it | "Tests passed" |
APPROVED |
Human signed off | Tech lead approved design |
INFERRED |
Across deduced it | Service B is affected |
DISPUTED |
Contradicted | Two sessions disagree |
SUPERSEDED |
Replaced | Decision replaced by later decision |
UNKNOWN |
No evidence | Anything uncited |
Critical rule: Never convert "the agent said tests passed" into "tests passed" without execution evidence (basis: executed_by_across_local_runner).
A durable checkpoint record linking engineering activity to a git revision. The revision is resolved with git rev-parse --verify when the checkpoint is recorded; the record itself is not cryptographically sealed or enforced immutable (agent-help reports immutable_enforced: false).
checkpoint_id, repository_id, revision, session_id,
created_at, message, basis, agent, native_session_id
Restore creates a new git worktree — never mutates your existing checkout.
Every revision relationship carries a basis:
| Basis | Meaning |
|---|---|
checkpoint_revision |
Caused by the checkpointed work |
capture_time_head_not_causation |
HEAD at capture time — not proven causal |
executed_by_across_local_runner |
Across executed and observed exit code |
user_recorded |
Human or agent claim, not independently verified |
unknown |
Provenance cannot be established |
across repo add PATH # Register external repo
across repo create NAME # Create hosted bare repo
across repo clone ID PATH # Clone
across repo list / show ID
across mirror create --repo ID
across mirror sync / status --repo IDacross session start --repo ID --agent NAME [--native-id N]
across session fork PARENT --repo ID --agent NAME [--native-id N]
# New session with parent_session_id + fork_type=fork
across session list / show ID / close ID
across source list [--repo ID]
across source import --repo ID --kind KIND --file F [--format FMT] [--native-id N]
# Formats: across, claude, cursor, codex, gemini, opencode
# F must be inside the repository root (see Security Model)
across agent import-session --agent NAME --repo ID --session SID --file F
across source inspect SOURCE_ID
across source delete SOURCE_ID # Tombstoned; the same native id or origin cannot be re-importedacross checkpoint create --repo ID [--session S] [--message M]
across checkpoint list / show / explain / compare A B
across checkpoint restore ID # → new worktree
across checkpoint bundle ID [--output F]
# Versioned, hashed evidence bundle (checkpoint + linked verifications)
across hook install REPO_PATH # Chains an existing post-commit hook
across hook uninstall REPO_PATH # Removes the Across hook, restores the chained original
across hook post-commit # Git hook entrypointacross memory create --repo ID --kind KIND --title T --body B
across memory list / show / approve / supersede OLD NEW
across search QUERY
across brief QUERY [--repo ID]
across handoff --session ID [--output F] [--format markdown|json]
across dossier --change CHANGE_ID
across context pack --repo ID --query Q [--session S] [--checkpoint CP] [--budget N] [--output F]
across context show MANIFEST_ID
across context diff --base R --head H --repo IDcontext pack builds a versioned, content-hashed manifest from the checkpoint boundary, approved memories and recent verifications, marking items that exceed the token budget as not included. Selection is deterministic; --query is required but does not yet rank or filter items. Handoffs, context manifests and checkpoint bundles are also recorded in the local store; there is no command to list the recorded copies yet.
across verify add --repo ID --name N # basis=user_recorded (STATED)
across verify run --repo ID --name N -- CMD...
# basis=executed_by_across_local_runner (OBSERVED)across code search QUERY [--repo ID]
across index --repo ID # Go AST; others heuristic
across graph query / impact / health / snapshot / diff
across why FILELINE [--repo ID] # git blame + checkpoint linkage
across investigate QUERY # Evidence-backed investigation
across review --repo ID # Deterministic checks (analysis ≠ verification)across issue create / list / show / comment / close
across change create / list / show / approve / request-changes
across branch-rule add --repo ID --pattern P [--min-approvals N]
across queue add / mergeacross control org-create / project-create / principal-create / grant
across token create / list / revoke
across serve [--addr 127.0.0.1:7681] # Loopback, bearer token, Git HTTP, web console
across mcp # Read-only MCP stdio server (8 store-backed tools)across doctor [--json]
across clean [--dry-run]
across activity / recap
across agent-help # Machine-readable JSON for coding agents
across agent list / info NAME
across plugin install / list / run / remove
across backup create --output F / verify FILE
across backup restore FILE --target-home DIR [--force]
# DIR must be new or empty; --force replaces an existing
# Across home and keeps it as DIR.across-old-TIMESTAMP
across versionErrors print as across: <code>: <message> on stderr. Exit codes: 2 invalid_argument, 3 not_found, 4 conflict, 5 operation_failed (including a failed verify run command), 1 internal.
across/
├── cmd/
│ ├── across/ # Main CLI
│ └── across-agent-*/ # 9 protocol-shell binaries (protocol v1, JSON stdio)
├── internal/
│ ├── cli/ # Command implementations
│ ├── config/ # ACROSS_HOME, --home
│ ├── store/ # SQLite, migrations, ID generation
│ ├── git/ # Git wrapper, safe hook installer
│ ├── event/ # Canonical events, native parsers, dedup
│ ├── adapter/ # Shared protocol-v1 shell for cmd/across-agent-*
│ └── redact/ # Deterministic secret redaction
├── web/ # Optional thin read-only console; browser qualification pending
├── docs/
│ ├── SECURITY.md
│ ├── agent-compatibility.md
│ └── research/clean-room-decisions.md
├── e2e/ # End-to-end tests
├── .github/
│ ├── workflows/ci.yml
│ ├── ISSUE_TEMPLATE/
│ └── PULL_REQUEST_TEMPLATE.md
├── CONTRIBUTING.md
├── CHANGELOG.md
├── CODE_OF_CONDUCT.md
├── LICENSE
├── Makefile
├── README.md
├── go.mod
└── go.sum
The default data directory is ~/.local/share/across/ (override with ACROSS_HOME or --home):
~/.local/share/across/
├── across.db # Main SQLite database
├── across.db-wal # WAL file
├── repositories/ # Hosted bare repos
├── mirrors/ # Local git mirrors
├── workspaces/ # Checkpoint restore worktrees
├── plugins/ # Installed plugins
├── backups/ # Backup archives
└── tmp/ # Temporary data (cleaned by `across clean`)
See docs/SECURITY.md for the full threat model and enforcement rules.
Key points:
- Retrieved context is data, never permission.
- Transcript imports (
source import,agent import-session) are canonicalized, symlink-resolved, size-bounded, and must be inside the registered repository root; a path outside it is rejected withtranscript path must be within the repository root. Copy a provider export into the working tree (for example an untracked or git-ignored directory) before importing it. - Hooks are chained, never silently overwritten: the original is preserved as
<hook>.across-origand runs from the Across wrapper (stdin-reading hooks such aspre-receivereceive the same input); ownership is marker-based andacross hook uninstallrestores the original. - Checkpoint restore creates a new worktree; never mutates your checkout.
- Backup restore is staged and validated (member list, checksums, modes, SQLite integrity) before it is committed by rename; it refuses a non-empty directory that is not an Across home and replaces an Across home only with
--force, keeping the previous one beside it. - Deleted sources are tombstoned; re-importing the same native id, or the same origin without a native id, is refused.
- The local runner is not a sandbox (user OS permissions).
- Plugins are not sandboxed.
- Secret redaction is best-effort.
across servebinds to loopback only and requires the bearer token for everything except/health; the browser console's cookie (set by opening/?token=…) is accepted only for same-origin requests, so pages on other localhost ports cannot use it.- HTTP authorization is not an OS/filesystem security boundary.
See docs/agent-compatibility.md for the full matrix and import workflow.
| Provider | Manual parser | Protocol shell | Provider integration |
|---|---|---|---|
| Claude Code | JSONL | protocol v1 | UNIMPLEMENTED |
| Codex | rollout JSONL | protocol v1 | UNIMPLEMENTED |
| Cursor | JSONL | protocol v1 | UNIMPLEMENTED |
| Gemini CLI | session JSON | protocol v1 | UNIMPLEMENTED |
| OpenCode | export; synthetic parser test | protocol v1 | UNIMPLEMENTED (parser evidence only) |
| Qwen Code | not implemented | protocol v1 | UNIMPLEMENTED |
| Factory Droid | not implemented | protocol v1 | UNIMPLEMENTED |
| Amp | not implemented | protocol v1 | UNIMPLEMENTED |
| Goose | not implemented | protocol v1 | UNIMPLEMENTED |
Provider integration qualification: UNIMPLEMENTED · SYNTHETIC_TESTED · LIVE_TESTED · LIVE_QUALIFIED · BLOCKED. Protocol-shell tests and manual parser tests do not qualify a provider integration.
make build # Build the core CLI and optional protocol-shell binaries
make test # All tests, including E2E
make test-e2e # End-to-end tests only (alias: make e2e)
make test-race # Race detector
make vet # go vet
make check # gofmt check + vet + test-race
make cross-check # Windows compile-only check (CGO disabled)
make vulncheck # govulncheck at the pinned version
make install-local # Copy binaries to ~/.local/bin/
make uninstall-localRequires Go 1.26.6 or newer (see go.mod), git, and a C compiler for cgo (the SQLite driver).
See CONTRIBUTING.md. One concern per commit. Evidence over confidence. make check before opening a PR.
- Browser UI — not qualified in a browser; the served assets are the checked-in files embedded in the binary
- Linux — CI runs the test suite on Linux; not otherwise qualified
- Windows — compile-checked in CI only; not tested
- Provider LIVE qualification — requires real provider sessions
- FTS5 search (portable substring index ships instead)
- Backup encryption (plaintext; protect externally)
- Session export via provider CLIs (import path enforces bounds)
- Merge queue auto-push (merge commit prepared in isolated clone; push manual)
- Memory state (
approved) means approved engineering context — not objective truth. capture_time_head_not_causationdoes not prove the agent caused the commit.- Anything not cited in a brief or dossier is UNKNOWN — Across does not invent confidence.
- Backups are plaintext unless protected externally.
- The local runner executes with user OS permissions (not a sandbox).
MIT © 2026 GrayCodeAI