patcharc 0.3.0macOS · Linux · Windows · no account needed locally
The verified story behind every change.
PatchArc records how a change happened, commit by commit, with the decisions and risks you noted on the way. It seals that record into an Ed25519-signed capsule anyone can verify offline, and publishes a server-verified link when you choose to share.
$ brew install patcharc01Goal
Rework session storage
02What changed
4 commits · 9 files · +418 −122
- a1b2c3dsessions: enable WAL mode2 files
- 4d5e6f7sessions: retry on SQLITE_BUSY3 files
- 8a9b0c1tests: cover concurrent writers3 files
- f9e8d7cdocs: note migration risk1 file
03Affected scopes
from workspace detection
- services/auth+300 −90major
- packages/client+18 −4minor
- cross-cutting+100 −28minor
04Verification
none recorded yet
no test runs recorded (test parsing ships in 0.3)
0 passed · 0 failed · 0 skipped
05Phases
grouped from commit order
- 1Phase 1, Foundation1 commit
- 2Phase 2, Implementation2 commits
- 3Phase 3, Verification and cleanup1 commit
06Decisions and remaining risk
recorded in one line each
- decisionKeep SQLite; Postgres is not justified below 50k sessions
- riskMigration on existing databases is untested
Signature valid. 9 of 9 file hashes match. Computed from evidence inside the capsule; no model involved.
arc_8f2c1d4a9b.parczip · stored · 48213 bytes
- manifest.jsonmanifest2.1 KB
- manifest.siged2551964 B
- manifest.pubed2551944 B
- arc.jsonmetadata412 B
- trust.jsonmetadata96 B
- redaction.jsonredaction188 B
- review.jsonsummary4.1 KB
- a1b2c3d.jsongit640 B
- a1b2c3d.patchgit9.8 KB
- index.jsonscope520 B
- file_changes.jsonmetadata1.3 KB
manifest.json, canonical (what the signature covers)
{
"format": "parc",
"format_version": "0.2.0",
"arc_id": "arc_8f2c1d4a9b",
"repository": {
"default_branch": "main",
"head_before": "a1b2c3d…",
"head_after": "f9e8d7c…"
},
"files": [
{ "path": "evidence/summary/review.json",
"size": 4120, "sha256": "9f1c2e…", "kind": "summary" }
],
"totals": { "files": 9, "bytes": 48213, "commits": 4 },
"trust": { "offline_verifiable": true, "redaction_applied": false }
}$ patcharc inspect .patcharc/capsules/arc_8f2c1d4a9b.parcCapsule: arc_8f2c1d4a9bFormat: 0.2.0Files: 9 (48213 bytes)✓ Signature: true✓ Manifest: true✓ Path traversal: true✓ Zip-bomb safe: true$ patcharc verify .patcharc/capsules/arc_8f2c1d4a9b.parc✓ arc_8f2c1d4a9b is valid (9 files, 48213 bytes, signed by 3f9a1c7e2b5d…)$ echo $?0
Seven checks
- 01Path safety
- 02Compression ratio
- 03Manifest entries present
- 04Manifest validity
- 05Ed25519 signature
- 06Every file hash and size
- 07Completeness
Exit 1 on any failure. The service repeats checks 3 to 6 before publishing a link.
Worked example from a sealed Arc. Fields match evidence/summary/review.json and manifest.json in 0.2.0.
- signature on every capsule manifest
- Ed25519
- signature on every capsule manifest
- hash on every file, checked on verify
- SHA-256
- hash on every file, checked on verify
- workspace detectors for monorepo scopes
- 10
- workspace detectors for monorepo scopes
- review sections, computed without AI
- 6
- review sections, computed without AI
- random ArcLink slugs, 30-day default expiry
- 96-bit
- random ArcLink slugs, 30-day default expiry
- accounts needed for the local loop
- 0
- accounts needed for the local loop
How it works
Four commands between you and a review that checks out.
The loop runs on your machine. The cloud only enters when you decide to share. Quickstart
1.0init
Initialize the repository
patcharc init creates .patcharc/ in your repo: a config file, a local SQLite session store, and a fresh Ed25519 signing key (0600) that never leaves the directory. It also adds two .gitignore lines so everything local stays out of Git, while config.yaml stays tracked for your team. No account, no network.
patcharc init~/src/your-repostage 1.0 $ patcharc init✓ Initialised PatchArc in ~/src/your-repoconfig: .patcharc/config.yamlkey: .patcharc/keys/arc-signing.ed25519 (mode 0600)database: .patcharc/session.db2.0record
Record the Arc while you work
patcharc start --detach runs a background observer that polls Git plumbing and records every new commit and the files it touched, across branches and worktrees, without hooks or changes to your working tree. Notes, decisions, risks, and checkpoints are one command each, so the reasoning is captured while it is fresh.
patcharc start --detach "what you are building"~/src/your-repostage 2.0 $ patcharc start --detach "Rework session storage"✓ Arc arc_8f2c1d started on main @ a1b2c3dgoal: Rework session storageobserver: detached (PID file: .patcharc/observer.pid)$ patcharc note 'WAL mode avoids the lock storm'$ patcharc decision 'keep SQLite, no Postgres yet'$ patcharc risk 'migration on existing dbs'✓ risk recorded3.0seal
Stop, seal, verify
patcharc stop builds the six-section review (goal, what changed, affected scopes, verification, phases, decisions and risks) from the recorded evidence and seals everything into a .parc: a ZIP with a canonical-JSON manifest, an Ed25519 signature, and the public key. patcharc verify checks the signature, every file hash and size, path safety, and the compression ratio, offline, and exits non-zero on failure.
patcharc stop && patcharc verify <capsule>~/src/your-repostage 3.0 $ patcharc stop✓ Arc sealed: .patcharc/capsules/arc_8f2c1d.parcinspect: patcharc inspect .patcharc/capsules/arc_8f2c1d.parcverify: patcharc verify .patcharc/capsules/arc_8f2c1d.parc$ patcharc verify .patcharc/capsules/arc_8f2c1d.parc✓ arc_8f2c1d is valid (9 files, 48213 bytes, signed by 3f9a1c7e2b5d…)4.0share
Share a link the server has verified
patcharc login uses a device flow: visit the URL, enter the code, approve with GitHub or Google. patcharc share uploads the sealed capsule, the cloud re-verifies the signature and every hash before it will publish anything, and you get an ArcLink with a random 96-bit slug. Revoke it and it returns 410; rotate it and the old slug dies.
patcharc share --visibility public~/src/your-repostage 4.0 $ patcharc loginTo authenticate, visit: https://patcharc.dev/device?code=KQ7P-MX2A-91ZCand enter code: KQ7P-MX2A-91ZC✓ Logged in to PatchArc Cloud$ patcharc share --visibility public✓ Uploaded arc_8f2c1d.parc (48213 bytes, sha256 9f1c2e…)ArcLink: https://link.patcharc.dev/a/X9kQ2mN4vR7s
What you get
Built like a tool, not a platform you rent.
Verifiable offline
A capsule is a ZIP with a signed manifest. Anyone holding the file can run patcharc verify with no account and no network; it exits non-zero if one byte changed. The cloud runs the same check before it publishes anything.
$ patcharc init✓ Initialised PatchArc in ~/src/your-repo$ patcharc start --detach "Rework sessions"✓ Arc arc_8f2c1d started on main @ a1b2c3d# commits, notes, decisions, risks$ patcharc stop✓ Arc sealed: .patcharc/capsules/arc_8f2c1d.parc$ patcharc verify .patcharc/capsules/arc_8f2c1d.parc✓ arc_8f2c1d is valid (9 files, signed by 3f9a1c7e…)$ patcharc share --visibility public✓ Uploaded arc_8f2c1d.parc (48213 bytes)ArcLink: https://link.patcharc.dev/a/X9kQ2mN4vR7s
Review without AI
The six sections are computed from recorded evidence: commits, touched files, scopes, and the notes, decisions, and risks you typed. There is no model in the loop, so the review is the same every time you seal the same Arc.
02What changed
4 commits · 9 files · +418 −122
- a1b2c3dsessions: enable WAL mode2 files
- 4d5e6f7sessions: retry on SQLITE_BUSY3 files
- 8a9b0c1tests: cover concurrent writers3 files
- f9e8d7cdocs: note migration risk1 file
03Affected scopes
from workspace detection
- services/auth+300 −90major
- packages/client+18 −4minor
- cross-cutting+100 −28minor
06Decisions and remaining risk
recorded in one line each
- decisionKeep SQLite; Postgres is not justified below 50k sessions
- riskMigration on existing databases is untested
- Monorepo-native
- Ten workspace detectors (pnpm, npm and yarn workspaces, Nx, Rush, Bazel, go.work, Cargo, Maven, Gradle, .NET) map a change to the packages it touched, or you declare scopes in config.yaml and they win.
- Links you can revoke
- ArcLink slugs carry at least 96 bits of entropy and expire in 30 days by default. Revoke one and it returns 410; rotate one and the old slug stops resolving immediately. Every share and revoke is an audit event.
- Device-flow sign-in
- patcharc login opens the approval page, you sign in with GitHub or Google, and the CLI receives its token. Credentials live in ~/.patcharc/credentials.json (0600), separate from the repo. Refresh tokens are hashed at rest and rotated on every use.
- Your keys stay sealedlater
- Provider keys registered for BYOK are envelope-encrypted: a per-connection AES-256-GCM key wrapped by a versioned master key, decrypted only inside an isolated key service with no public endpoint. No API ever returns a key. AI summaries that use them are not produced yet.
- Redaction engine
- Thirteen detectors (AWS, GitHub, Slack, Stripe, OpenAI, Anthropic, Google keys, PEM blocks, JWTs, connection strings), env-file rules, and entropy scanning run over every diff when the capsule is sealed. The signed redaction report records what was removed; inspect a capsule before you share it all the same.
- Tests become evidence
- patcharc run wraps any command: go test, pytest, vitest, jest, playwright, and cargo results are parsed into the review's Verification section, JUnit XML imports with --junit, and the exit code passes through so CI pipelines wrap it safely. An Arc with no recorded tests says so, rather than showing zeros as a clean run.
- Knows who wrote what
- Commits carrying agent trailers or agent committer identities are attributed automatically: each commit reads agent, assisted, or human in the sealed review, derived from Git evidence rather than anyone's say-so. The counts and the agents involved appear in every capsule and every shared link.
- Any agent, one integration
- patcharc mcp serves the recorder over the open agent-tool protocol: Claude Code, Codex, Cursor, and anything else that speaks it can start and seal Arcs, record decisions and risks, and file test results as it works. No per-agent adapter required; commits alone are enough even without it.
- Ambient capture, opt-in
- patcharc hooks install adds append-only git hooks that reconcile commits the moment they land and record rebases and amends as rewrite evidence; with init --auto, a commit made with no Arc active opens one by itself. Every hook line is designed so PatchArc can never fail a commit.
- Attestations for provenance pipelines
- patcharc attest re-expresses a verified capsule as a signed in-toto statement, binding the resulting commit and the capsule digest to the recorded process evidence. Standard provenance tooling can consume the story of a change without learning a new format.
- No telemetry, hooks only by choice
- The observer reads Git plumbing on a 1.5 s poll and the local loop makes no network calls. Git hooks are installed only when you ask, via patcharc hooks install or init --auto, are append-only, and can never fail a commit. Delete .patcharc/ and nothing of yours remains anywhere we operate.
Architecture
Two planes, one contract.
Everything that matters runs on your machine, and the service has to prove a capsule before it publishes it. The capsule format is documented; nothing inside a capsule depends on us.
Read the security pageOn your machine
- Capture, review, seal, verify, inspect
- Documented .parc format and manifest
- Deterministic six-section review
- Workspace detection for monorepos
Hosted service
- Upload and server-side re-verification
- ArcLinks with revoke and rotate
- Device-flow sign-in (GitHub, Google)
- Sealed storage for BYOK provider keys
Compared, fairly
PatchArc is not a code reviewer and not a transcript recorder.
ADR tools compared, and decisions captured in the flow
adr-tools, Log4brains, dotnet-adr, and the Backstage ADR plugin for architecture decision records, next to recording decisions with patcharc decision while the change is being made.
CodeRabbit vs Greptile
A neutral head to head on how each reviews a pull request, what each stores, what each costs, and what neither of them records.
PatchArc vs Entire
The two closest tools for recording what an AI coding agent did: Entire stores full transcripts on a Git branch; PatchArc seals a signed, deterministic review capsule. Where each fits and where both can run together.
PatchArc vs Lore
Two ways to hand off an AI coding session: Lore shares the raw transcript with a fork prompt; PatchArc shares a sealed, verifiable review. Pricing, privacy, and which to pick.
Before installing
Questions people ask.
- Do I need an account?
- No. Everything except share runs with no account and no network. You sign in only when you publish a link.
- When does my code leave my machine?
- Only when you run patcharc share. What uploads is the sealed capsule, and the service re-verifies it before a link exists.
- Does the review need AI?
- No. The six sections are computed from recorded evidence. AI summaries are planned on top; none are generated yet.
- Who can open an ArcLink?
- Only you, by default: share reads share.default from your repo config, which starts as private. Public links are an explicit choice, expire after 30 days, and you can revoke or rotate one at any time.
- Can I read a capsule without PatchArc?
- Yes. It is a ZIP with a documented manifest: unzip it and read the review and every patch with any text tool.
- What about monorepos?
- Ten workspace detectors map a change to the packages it touched, so the review is organised by scope rather than by file path.
- Does it work with Claude Code, Codex, or Cursor?
- Yes. An agent's commits are recorded the same way yours are, agent trailers and identities are attributed automatically, and patcharc mcp gives any MCP-capable agent tools to record decisions and test results itself. Transcript capture is planned, not built.
- Are secrets redacted?
- Yes, at seal time. Every diff passes through the redaction engine when stop seals the capsule, and the signed redaction report records what was removed. It is a guardrail, not a guarantee: read a capsule with patcharc inspect before you share it.
01
02
03
04
05
06
07
08
Seal your next change.
Install the CLI, record an Arc in any Git repository, verify it offline. Share it when you are ready.
$ brew install patcharc