
Security News
Insecure Agents Podcast: How to Keep AI Agents From Bypassing Security Controls
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.
superlog-cloud
Advanced tools
Connect a machine to super-log Cloud: enrolment, uplink daemon, and journal seeding
Connect a machine to super-log Cloud: enrolment, the uplink daemon, and journal seeding.
This is the proprietary half of super-log. The MIT project — the hub, the viewer and the forty-odd tailers — is a separate install and carries no cloud code at all. Nothing here is required to run super-log locally.
Source-published for audit, which is a different promise from open source
and the one that actually matters for this tool: a program that decides what
leaves your machine should be readable by the person whose machine it is.
Everything it sends is printed by superlog-cloud explain; everything it
stores is one 0600 JSON file you can cat.
npm install -g superlog-cloud
Or run it without installing anything:
npx superlog-cloud login
The package name is deliberately unscoped even though the sibling packages
are @super-log/*. npx <pkg> runs the binary whose name matches the last
segment of the package name; as @super-log/cloud that segment is cloud,
there is no such binary, and npx fails with cloud: command not found.
Unscoped, the segment is the binary name, and npx superlog-cloud login
works with nothing installed — which is the whole point of offering it.
Requires Node 22 or newer — the uplink uses the global WebSocket that
arrived in Node 22. Zero dependencies.
Two entry points, same ceremony, because which end starts depends on which end the human is already holding.
From the machine (a server nobody is sitting at). It prints a code and a URL first, unconditionally, then waits:
superlog-cloud login
From the browser (you just signed up or paid, and the console showed you a code). The code is a one-time claim on a consent, not a credential — it is dead after redemption or fifteen minutes:
superlog-cloud login --code XXXX-XXXX
Then start the uplink:
secure-superlogd --url https://api.super-log.com \
--token "$(superlog-cloud token)" --bench my-bench
| Command | What it does |
|---|---|
superlog-cloud login | Device-code enrolment; prints a code and a URL, then polls |
superlog-cloud login --code XXXX-XXXX | Redeem a pre-approved code from the console |
superlog-cloud status | Enrolled? which org, which bench, is the uplink up, is it paused |
superlog-cloud seed --journal DIR | Upload history this bench already has, so day one is not an empty room |
superlog-cloud pause / resume | Stop sending without unenrolling |
superlog-cloud logout | Remove the local credential |
superlog-cloud explain | The endpoint, the exact headers and payload, and what is never sent |
superlog-cloud token | Print the bench token, for scripts |
secure-superlogd | The uplink daemon: forward a hub's firehose to the cloud |
superlog-cloud login --url URL (or SUPERLOG_CLOUD_URL) points the whole
thing at a staging deployment. With no flags it reaches production.
~/.superlog/cloud.json — the bench credential, mode 0600. Never printed.~/.superlog/cloud.paused — the stop tap. A file, not a socket and not a
signal: the daemon accepts no inbound connection by design, and a file is
the one control you can ls, set from any shell, and leave in place
across a reboot.Proprietary. See LICENSE.
FAQs
Connect a machine to super-log Cloud, and read the team's journal from any editor or shell: enrolment, uplink daemon, logs, search and readings
The npm package superlog-cloud receives a total of 184 weekly downloads. As such, superlog-cloud popularity was classified as not popular.
We found that superlog-cloud demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.

Security News
Socket CTO Ahmad Nassri discusses how to keep AI agents from bypassing package blocks, limit credential access, and monitor their actions.

Security News
GPT-6 Astra tried to plant malicious code in simulated open source projects using fake GitHub accounts and deceptive PRs during an assigned CTF challenge.

Security News
upm uses Node.js to deliver fast npm installs in about 250 KB, with a JavaScript API and security defaults.