Skip to main content
The holm CLI is your control plane — where you add agents and servers and govern what each agent can reach. Agents don’t run it; they act on the action plane over the daemon’s MCP endpoint. Commands read verb-first — holm <verb> <resource> [name]. The verbs are add, remove, list, show, grant, revoke, and rotate; the resources are server and agent. Daemon lifecycle (start, stop, status, serve) and version / update round out the surface.

Servers

Servers are the MCP servers you want agents to reach through Steerholm. Adding a server registers it with the daemon, which handles starting and stopping the server processes.

holm add server

Register a new MCP server. Provide --command for stdio servers or --url for HTTP servers (not both); the server type is inferred. Pass config or secrets to a stdio server with --env (repeatable).
--env names must be letters, digits, _, -, or . and can’t start with a digit (the Kubernetes/Docker rule, for cross-platform portability); a repeated name is an error. Values may contain anything, including =.

holm remove server

Remove a server from Steerholm.

holm list servers

Show all servers with their transport type and live status (state, uptime, and tool count when the daemon is running).

holm show server

Show a server’s configuration, its live status, the tools it provides, and which agents have been granted access to it.

Agents

An agent has a name and an access key. The access key is what the agent uses to authenticate — Steerholm resolves the agent from the key, so agents cannot impersonate each other.

holm add agent

Add an agent and generate its access key. The key is shown once and cannot be retrieved later — store it when it’s printed.

holm list agents

Show all agents and their access-key prefixes.

holm show agent

Show an agent: its access-key prefix, everything it can reach (server → tools → argument constraints), and how to connect it with its key.

holm rotate agent

Generate a new access key for an agent, keeping all of its grants. The previous key stops working immediately — update the agent’s config in its tool with the new key.

holm remove agent

Remove an agent, its access key, and its policy. The key is revoked immediately.

Access (grants)

An agent’s policy is default-deny: with no grants it has zero access. Grants are additive — each grant adds a rule.

holm grant

Grant an agent access to a server’s tools.
Allow all tools on a server:
Allow a specific tool:
Restrict by argument value (glob):
Restrict by argument value (regex):
Multiple argument restrictions on one tool:
A glob pattern without wildcards is an exact match. An argument policy applies only when the tool call actually provides that argument.

holm revoke

Remove an agent’s access to a server. With --tool it removes only that tool grant; without it, the agent’s entire access to the server is removed. --tool matches the exact pattern you granted (e.g. git_diff*), not a glob expansion of it — so revoke the same pattern you used in grant.

Daemon

The daemon is the long-running process that exposes the Streamable HTTP MCP endpoint, manages server connections, and enforces policies. Installation registers it as a per-user background daemon that runs as you (no admin required) and starts automatically at login.

holm start

Start the daemon via the platform’s per-user service manager (systemd --user, a launchd agent, or a Windows logon Scheduled Task).

holm stop

Stop the daemon. All active agent sessions are disconnected.

holm status

Check whether the daemon is currently running.

holm serve

Run the daemon in the foreground instead of as a service. Useful for debugging — logs go to stderr.
Steerholm binds to loopback (127.0.0.1) by default. Binding to a non-loopback host like 0.0.0.0 exposes the endpoint — and its tool access — to your network, and access keys travel as Bearer tokens over plain HTTP. Only do this on a trusted network, ideally behind a TLS-terminating reverse proxy.

Version & updates

holm version

Print the installed Steerholm version. holm --version does the same.

holm update

Update Steerholm in place from a GitHub release (the latest by default). It downloads the release for your platform, verifies it against the published checksums, and runs the official install script.