# Estelle documentation

## Introduction | introduction
Estelle is the trust layer under your AI coding agents. It provides persistent memory, repository verification, and code review with evidence. Keep your existing coding agent and model. Estelle connects through its plugin, hosted MCP server, CLI, and dashboard.

## Install in Claude Code | quickstart
Run these two commands in Claude Code:
/plugin marketplace add uqeu/estelle-cli
/plugin install estelle@fatelabs
Restart Claude Code, approve the Estelle MCP connection, and sign in to your Estelle account. Ask your agent to call estelle_resume to check the connection and recover existing context. The plugin includes the MCP configuration and session hooks.

## Install in Codex | quickstart
Run these two commands in your shell, outside the Codex conversation:
codex plugin marketplace add uqeu/estelle-cli
codex plugin add estelle@fatelabs
Open Codex, run /hooks and trust the installed hooks. Approve the Estelle MCP connection, sign in, and restart the session. Ask your agent to call estelle_resume. Untrusted hooks do not run: installation alone does not activate them. In Codex 0.153.4, the SessionEnd time limit can defer checkpoints until the next session starts; Stop and SubagentStop do not execute in that version.

## Connect over MCP | mcp
The hosted MCP endpoint is https://api.fatelabs.ca/mcp. Use your client’s OAuth sign-in flow and approve the connection. The plugin includes this configuration. For standalone Claude Code MCP setup, use:
claude mcp add --transport http estelle https://api.fatelabs.ca/mcp
Keep choosing your model in your coding client. Estelle credentials and model-provider credentials are separate.

## Command line | cli
Install the native CLI from the published release:
curl --proto '=https' --tlsv1.2 -fsSL https://github.com/uqeu/estelle-cli/releases/latest/download/install.sh | sh
Then run estelle login, estelle setup, and estelle. Run estelle doctor to diagnose the connection. Use estelle sweep to refresh the repository index. In the terminal, /login connects your model account and /model selects a model. estelle setup --dry-run previews local configuration changes.

## Workspace navigation | dashboard
Overview summarizes completed work, active work, upcoming work, monitoring, and saved knowledge from the records your account can access. Ask Estelle is for questions about your work. Graph explores code and stored relationships. Memory contains saved knowledge. Sessions lets you return to conversations. Monitoring investigates production signals. Agent work shows jobs and their evidence. Console is the repository development surface. Code & connections manages connected sources. Workspace settings contains account, team, billing, profile, and preferences.

## Connect a repository | connections
Use Add repository or Code & connections in the dashboard to connect repositories through your GitHub integration. Grant access only to the repositories you want Estelle to use. A connected integration does not imply that all historical data has been imported. Inspect the indexed revision and coverage before relying on a code result.

## Explore code | code-graph
The code graph represents files, symbols, definitions, and dependencies in a repository. Select a symbol to inspect its source and relationships. Use find_definition and locate to find real definitions; use find_usages and blast_radius to inspect callers and change impact. A stale or missing index cannot prove a symbol is absent. Refresh the repository and retry when Estelle reports insufficient coverage.

## Memory and sessions | memory-workspace
The memory library organizes persisted knowledge cards and their sources. Saved cards can include decisions, project context, concepts, and records distilled from sessions. Open a card to read its body, inspect sources, and see saved versions. Distil sessions extracts knowledge from available session records. No new cards can mean either no input runs or no new durable knowledge; the result reports that distinction. Sessions is a conversation history, not a count of concurrent agents.

## How memory works | memory
Call estelle_resume at the start of a session to recover relevant context. list_sessions and get_session revisit earlier conversations. memory_chat asks about saved knowledge. estelle_checkpoint preserves context for a later session. Persistent memory can carry decisions and their rationale across restarts and context limits. Retrieval is scoped to the account and team permissions. A source citation gives provenance; it does not automatically prove every conclusion in a memory.

## Grounding and refusals | grounding
Use verify to check a claim against repository evidence. gate checks a proposed diff deterministically; review adds a rival model review. Findings point back to code evidence. A refusal such as could-not-verify, not swept, or stale means Estelle lacks sufficient current evidence. It is not proof that the symbol is absent or that the code is wrong. Refresh the index or provide the missing evidence and retry. A clean local test is evidence about that test, not a production deployment.

## MCP tools | tools
Repository navigation: verify, find_definition, locate, find_usages, blast_radius, dependency_path. Change checks: gate and review. Persistent context: estelle_resume, list_sessions, get_session, memory_chat, estelle_checkpoint. External package research: research_ask. Production investigation: monitor tools on entitled plans. Use skill_find to discover available workflows. Tool availability depends on the connection, configured capabilities, and account entitlements.

## Automatic pull request review | pr-review
Connect the Estelle GitHub App and enable inline review for the repository. Pull request opened, synchronize, and reopened events can trigger review. Mention @estelle review for a manual review. Findings are posted as review comments. The default workflow proposes changes for a human to review and merge.

## Monitoring | monitoring
Monitoring connects production signals to affected code and reviewable repair evidence. Inspect logs, alerts, uptime, and subjects in the dashboard. An empty issue feed does not prove that monitoring is connected or that a service is healthy. Check available service coverage and the selected time window. Stored counters without retained traces are not proof of current traffic. Production monitoring features require the appropriate account entitlement.

## Permissions and autonomy | autonomy
The default is propose-only: Estelle proposes a grounded fix, checks it through the gate and reproduction tests, and presents a reviewable pull request. Autonomy is opt-in, tiered, and proof-gated. Auto-merge requires explicit opt-in and passing verification; failing a guard falls back to a reviewable PR. Protected changes involving auth, billing, schema, security, or deployment remain human-gated. Auto-deploy is not shipped. Workspace settings contains the autonomy controls.

## Authentication | authentication
Plugin and hosted MCP connections use OAuth sign-in. Direct API calls use an Estelle bearer token in the Authorization header. Production Estelle keys start with estelle_live_. Create and revoke keys in Dashboard → API keys. Keep credentials in environment variables or a secret manager, not source control. Never paste an API key into the docs chat. A model-provider key is separate from your Estelle account credential.

## Call the API | api
The OpenAI-compatible API base URL is https://api.fatelabs.ca/v1. The model id is estelle. Send Authorization: Bearer with your Estelle credential. GET /v1/models lists the available model surface. POST /v1/chat/completions accepts the OpenAI-style messages array. Keep secrets on your server. Your provider connection supplies the underlying model.

## Chat completions | chat
POST https://api.fatelabs.ca/v1/chat/completions with a JSON body containing model: estelle and messages: an array of role/content messages. Send Content-Type: application/json and Authorization: Bearer with your Estelle key. Use a non-streaming request. The endpoint returns the completed answer in a JSON response at choices[0].message.content. Estelle chooses its sampling settings; the documented endpoint does not support response_format. Consult the API reference for complete request fields.

## Errors and limits | errors
An authentication error means the credential could not be accepted. An entitlement or budget error needs account or plan review. Rate limits require backing off and retrying. A grounding refusal is an evidence result, not an authentication error. Never interpret an unavailable data source as a zero count. For account-specific billing, usage, and access questions, sign in and explicitly include your account in Ask AI.

## Models and providers | providers
Keep the model and plan you already use. Plugin users select their model in the host coding client. Native CLI users connect their model account with /login and select it with /model. Estelle’s account credential and model-provider connection have separate purposes. See the provider guides for the supported login or API-key setup for your provider.

## Teams and roles | teams
Workspace settings → Team manages your team and permitted membership actions. Access depends on your role and the repositories granted to the workspace. Your personal profile appears across the workspace. Account-specific membership and billing information requires a signed-in session; the public documentation cannot infer your team’s configuration.

## Pricing and billing | billing
Current plan prices are available on the Pricing page. Your active plan, usage, and balance are shown under Workspace settings → Billing and Usage. Estelle uses your configured model-provider connection. Do not infer a visitor’s plan from public pricing or from another account. Account changes such as cancellation, payment changes, or changing autonomy must be made explicitly in the dashboard; the docs assistant is read-only.

## Support | support
Use the documentation to set up your agent and investigate connection problems. Run estelle doctor for CLI connection diagnostics. Contact Fate Labs through the site’s Contact page for help. Never include secret keys in a support message or a docs question.

## BYOK and privacy | privacy
Over MCP, reasoning stays on your existing coding client’s model connection. On Estelle’s API path, the model comes from the provider configured in Workspace settings → Model pool. Provider credentials are stored encrypted at rest and are not returned by account read endpoints. Your Estelle key is stored as a hash. The docs assistant is separate: it uses a server-side model connection to answer public documentation questions. Including your account is an explicit choice and shares only limited account fields and relevant repository names, session metadata, job states, and monitoring counts with that model, not your API keys, repository contents, or private memories.

## List models | models
GET https://api.fatelabs.ca/v1/models lists the models available to your Estelle credential. The documented model id is estelle, which routes to your configured provider. Use Authorization: Bearer with your Estelle credential. This is a connectivity check for the API base URL and credential.

## Rate limits | limits
A 429 response means a request limit was reached. Honor Retry-After when present and retry with exponential backoff. Account-specific limits depend on the service and plan. Ask AI has separate question limits; its model calls are not an unlimited public API. Check current pricing and the account’s Usage page for the relevant plan information.
