55
Seatbelt is an open source tool that records what AI agents do, in a way you can trust later. Every prompt, model response and tool call is written to a log file, one file per run. That log is built so you can tell if anyone has changed it afterwards.
Think of it as a dashcam for AI agents. It doesn't drive the car or stop the crash, but when something goes wrong you have footage you can rely on.
Where it sits
Seatbelt sits between the agent and the model provider. The agent thinks it's talking to Anthropic, OpenAI or Google as normal, but the traffic goes through seatbelt first. Seatbelt passes each request on, passes the answer back, and records both. Because it understands each provider's format rather than one specific model, it works with Claude, GPT and Gemini, and with tools like Claude Code, Codex and Gemini CLI.
How the record is protected
Each entry in the log carries a fingerprint (a hash) of the entry before it, so the entries form a chain. If someone edits, deletes or reorders an entry, the chain breaks, and seatbelt verify tells you exactly which entry is the first bad one. When a run ends, seatbelt also signs it with a key. That catches someone rebuilding the whole chain or cutting off the end of it.
Before anything is written, known secrets like API keys, tokens and passwords are stripped out. The record shows that a secret was there but never what it was.
Two ways to use it
On your own machine. seatbelt run claude wraps the CLI. You use it as normal, and when you exit the run is saved and signed locally. It's good for seeing what your own agents do. The catch is that the signing key lives on the same machine, so an agent that can run commands could, in theory, rewrite its record and re-sign it. The docs say so plainly.
Through a gateway, for a team. An organisation runs seatbelt on a separate server. Everyone's agents point at it, and it holds the provider keys and the signing key. Each person gets their own key, so you know who did what. The gateway can also restrict which models and tools are allowed and ship the records off to locked storage. The agent never gets near the key.
For Claude Enterprise, seatbelt can also pull in conversations the gateway never sees, such as claude.ai chats and Cowork sessions, through Anthropic's Compliance API.
What you can do with the records
reconstruct replays a run as a readable timeline.
report summarises usage by person, model and tool, and flags anything refused, broken or unsigned.
erase removes one person's records on request, inside a signed record of what was removed, so the deletion itself is auditable.
Testing agents, not just watching them
Seatbelt also ships a set of attack scenarios, including prompt injection, smuggled tool arguments and attempts to leak credentials. Each one is mapped to the OWASP Top 10 for Agentic Applications and, where one exists, MITRE ATLAS. You run them against your agent, optionally in a locked-down container with no network, and seatbelt checks the record for what the agent actually did. The results can be bundled into a single signed evidence pack that anyone can verify offline.
Status
It's pre-1.0, so the log format can still change. It's installable with uv tool install seatbelt-ai.
Built with