Features
What Whyline does today, grouped by what you use it for. A short list of things it does not do is at the end.
Capture
Agent hooks
Records each prompt you submit and each file the agent edits, in Claude Code (a plugin), Cursor, Codex CLI and Gemini CLI (their own hook files).
The reason is saved when the change is made, not reconstructed later.
Git post-commit hook
whyline init installs a hook in the repository. Every commit becomes an event with its hash, author email, message and changed files. It follows core.hooksPath. An existing shell hook is kept and still runs; a hook in another language is never edited, and init tells you how to add the call yourself. Running init twice does nothing. A post-rewrite hook keeps the agent and prompts when commits are amended or rebased.
Works for any tool that commits, with no agent-specific integration.
Agent detection from trailers
A commit is attributed to an agent when its message has a Co-Authored-By: or AI-Agent: trailer, or an Assisted-by: trailer (the Linux kernel's convention), that identifies claude-code (Claude), cursor, copilot, codex, gemini, aider, devin or windsurf itself. People who merely share an agent's name are not mistaken for it.
One record format across agents, with no vendor lock-in.
Prompts linked to commits
When a commit includes files a connected agent edited, the commit is attributed to that agent and carries the prompts from that session.
Blame can show the prompt, not only the commit message.
Find the answer
whyline blame file:line
Finds the commit for a line with git blame, then prints the agent, author, time, message and prompt recorded for it.
Answer “why is this here?” without leaving the terminal.
whyline events
Lists recent events as tab-separated rows. --since <id> shows only newer ones.
Easy to pipe into other tools.
Dashboard timeline
A newest-first timeline of the latest 500 events. Filter by file, prompt, agent, author or commit hash. Shows how many of the commits shown were AI-assisted, and by which agent, for the whole team or whatever the filter narrows it to.
Review what agents did across a whole team in one place.
CSV export
Downloads the full history, paging through every event, with id, time, agent, kind, author, commit, session, summary, prompt and files. Cells that start with =, +, - or @ are escaped so spreadsheets do not run them as formulas.
Hand a complete record to a reviewer or load it into your own tools.
Reliability and privacy
Offline queue
Events that cannot be sent are kept in a local file and sent with the next successful event. Invalid events, and events sent with an API key the server rejects, are dropped. Every event has an ID, so one sent twice is stored once.
Working offline does not silently skip events.
Hooks stay out of the way
Silent on stdout, always exit 0, and time out (5 seconds for the Claude Code hooks, 4 seconds per API call).
A Whyline problem never blocks your commit or the agent.
Prompt text opt-out
--no-prompts or WHYLINE_NO_PROMPTS=1 records that a prompt happened without sending or remembering its text.
Keep sensitive prompts on your machine.
Hashed keys
Workspace API keys are stored as SHA-256 hashes. Signup IP addresses are stored as hashes and used to rate-limit workspace creation to 10 per hour.
A database leak does not reveal usable keys.
Key rotation and deletion
whyline rotate-key replaces a workspace's key; the old one stops working at once. whyline delete-workspace --yes deletes the workspace and all of its events.
A leaked key is a one-command fix, and your data leaves when you do.
Run it your way
Self-host or deploy your own
Run the server locally with SQLite, or deploy it to Vercel with Supabase. Both use the same API.
Keep events on infrastructure you control.
Small HTTP API
Five routes, authenticated with a Bearer key except signup. Documented in the API reference.
Send events from any tool that can make an HTTP request.
Not available today
Stated plainly so you can judge fit.
- Prompts and individual edits are captured for Claude Code, Cursor, Codex CLI and Gemini CLI. Other agents are recorded at commit time. Codex edits made by shell commands, and Cursor Tab completions, are not recorded.
- A commit is attributed to an agent only if its message names one, or if a connected agent's edits were recorded locally. Otherwise it is recorded as
none. - A workspace is accessed with a single API key. There are no user accounts or per-person permissions.
- A lost key cannot be recovered, only replaced. Single events cannot be deleted, only a whole workspace.
- A squash merge made on GitHub creates a commit that no hook sees, so it has no record and no prompts.
- The dashboard lists the newest 500 events, and its AI share counts commits, not lines. Export CSV for the full history.