dreambuild
v0.5.0
Published
Connect Claude Code to DreamBuild: real-time directives, plus encrypted cross-device session resume.
Maintainers
Readme
dreambuild
Connect a repo's Claude Code sessions to DreamBuild — directives written by the project's owner reach the working agent in real time, at turn boundaries: when a session starts, when certain files are touched, before the agent finishes.
It also carries your sessions between machines, so you can stop on one and pick up on another with the whole conversation intact.
Install
From the root of the repo you want supervised:
pnpm dlx dreambuild init <project-slug> --token dbt_xxx(npx dreambuild init … works too.) The dbt_ value is a single-use
install token from your project's Directives tab — it expires in 10
minutes and is exchanged server-side for your API key, so the key never
appears on screen or in shell history. For CI or manual setups,
--key db_xxx with a key from the Settings page still works. Author
directives in the Directives tab.
What it installs — and what it doesn't
- A 6KB dependency-free hook script at
~/.foremen/hook.js. Claude Code runs it at turn boundaries; it asks the server "any directives for this moment?" and injects the answer. Any failure exits silently — it can never break a session. - A session-sync worker at
~/.foremen/session-sync.js, which the hook spawns in the background when the agent stops. If it cannot get an encryption key it uploads nothing at all — there is no plaintext path. - Registrations for five hook events plus your API key in
.claude/settings.local.json— the personal, git-ignored settings file, so the key never lands in the repo. - The full MCP connection (project memory: session briefs, tasks, decisions,
activity) in
.mcp.json. That file references${DREAMBUILD_API_KEY}instead of the key itself, so it is safe to commit — teammates who runinitget their own key locally and the same shared config just works.
DreamBuild itself stays on the server. Nothing else is installed, no
dependency is added to your project, and re-running init is safe
(idempotent).
Cross-device sessions
Stop working on your laptop, open the same repo on another machine, and carry on in the same conversation — nothing to re-explain.
dreambuild sessions # what you can pick up here
dreambuild resume # continue the most recent session
dreambuild resume <id> # or a specific oneThere is no setup step. Any repo wired with init syncs its sessions each time
the agent stops, and only the bytes added since last time go up — so a long
session costs almost nothing to keep current.
Already have history? Claude Code has been keeping transcripts all along, so sessions from before you installed this can be carried up too:
dreambuild backfill --dry-run # see how much there is first
dreambuild backfill # last 30 days
dreambuild backfill --all # everything on this machine for this repoRun it from the repo whose history you want. It is safe to re-run — anything already synced is skipped.
How your data is handled. Claude Code's own transcript is the thing being carried. Before it leaves your machine it is run through a redaction pass that strips known credential shapes (API keys, JWTs, tokens, private keys), and then encrypted. The encryption key is issued to devices already authenticated to your account and cached locally, which is what makes it zero-setup.
Two things worth stating plainly:
- This is encryption at rest, not end-to-end. A stolen database dump or leaked backup is useless on its own. But the server issues the key, so it could decrypt if it chose to. If you need the server to be incapable of reading your sessions, this is not that.
- Redaction is defence in depth, not a guarantee. It catches formats it knows. It cannot recognise an arbitrary password or a customer's details sitting in a query result — which is why the payload is encrypted too.
Your code does not travel. The conversation does. resume compares the
git branch and commit the session was on against the machine you are resuming
on and warns you when they differ — pull or check out that commit first if you
want them to match.
Turn sync off for a session with DREAMBUILD_SESSION_SYNC=0. Without a
key, nothing is ever uploaded.
Uninstall
pnpm dlx dreambuild uninstall # unwire this repo
pnpm dlx dreambuild uninstall --purge # also delete ~/.foremen (all repos)--purge also deletes this device's cached session key. It is re-fetched
automatically the next time you run dreambuild sessions or resume.
Other agent platforms
Directives also travel over MCP: session-start directives arrive inside
get_session_brief, task directives inside start_task, and the rest via
the check_directives tool — no hook required.
