holm CLI is your control plane — where you add
agents and servers and govern what each agent can reach. Agents don’t run it; they
act on the action plane over the daemon’s MCP endpoint.
Commands read verb-first — holm <verb> <resource> [name].
The verbs are add, remove, list, show, grant, revoke, and rotate;
the resources are server and agent. Daemon lifecycle (start, stop,
status, serve) and version / update round out the surface.
Servers
Servers are the MCP servers you want agents to reach through Steerholm. Adding a server registers it with the daemon, which handles starting and stopping the server processes.holm add server
Register a new MCP server. Provide--command for stdio servers or --url for
HTTP servers (not both); the server type is inferred. Pass config or secrets to a
stdio server with --env (repeatable).
--env names must be letters, digits, _, -, or . and can’t start with a
digit (the Kubernetes/Docker rule, for cross-platform portability); a repeated
name is an error. Values may contain anything, including =.holm remove server
Remove a server from Steerholm.holm list servers
Show all servers with their transport type and live status (state, uptime, and tool count when the daemon is running).holm show server
Show a server’s configuration, its live status, the tools it provides, and which agents have been granted access to it.Agents
An agent has a name and an access key. The access key is what the agent uses to authenticate — Steerholm resolves the agent from the key, so agents cannot impersonate each other.holm add agent
Add an agent and generate its access key. The key is shown once and cannot be retrieved later — store it when it’s printed.holm list agents
Show all agents and their access-key prefixes.holm show agent
Show an agent: its access-key prefix, everything it can reach (server → tools → argument constraints), and how to connect it with its key.holm rotate agent
Generate a new access key for an agent, keeping all of its grants. The previous key stops working immediately — update the agent’s config in its tool with the new key.holm remove agent
Remove an agent, its access key, and its policy. The key is revoked immediately.Access (grants)
An agent’s policy is default-deny: with no grants it has zero access. Grants are additive — eachgrant adds a rule.
holm grant
Grant an agent access to a server’s tools.
A glob pattern without wildcards is an exact match. An argument policy applies
only when the tool call actually provides that argument.
holm revoke
Remove an agent’s access to a server. With--tool it removes only that tool
grant; without it, the agent’s entire access to the server is removed. --tool
matches the exact pattern you granted (e.g. git_diff*), not a glob expansion of
it — so revoke the same pattern you used in grant.
Daemon
The daemon is the long-running process that exposes the Streamable HTTP MCP endpoint, manages server connections, and enforces policies. Installation registers it as a per-user background daemon that runs as you (no admin required) and starts automatically at login.holm start
Start the daemon via the platform’s per-user service manager (systemd--user, a
launchd agent, or a Windows logon Scheduled Task).
holm stop
Stop the daemon. All active agent sessions are disconnected.holm status
Check whether the daemon is currently running.holm serve
Run the daemon in the foreground instead of as a service. Useful for debugging — logs go to stderr.Version & updates
holm version
Print the installed Steerholm version.holm --version does the same.