Permissions: what Katman can do
Katman reads the files in your project but never your secrets, writes only to the .katman folder unless you explicitly ask for a generated file, and makes network calls only when a tool needs them. It contacts katman.pro for two things only: a plan check, at most once a day, that sends your KATMAN_KEY and the MCP version, and katman_sync, which sends a project summary only when you call it. Code, file contents, AI answers and your OpenRouter key are never sent to katman.pro.
In short
| What Katman does | |
|---|---|
| Reads | Files under your project root, except dependencies, build output and secrets |
| Writes | Only the .katman/ folder, plus two opt-in files you ask for, and a licence cache in ~/.katman/license.json |
| Network | Only when a tool needs it: your site, OpenRouter, IndexNow, Google autocomplete, and katman.pro for the plan check and katman_sync |
| katman.pro | Your key and the MCP version, at most once a day, for the plan check; katman_sync summaries only when you call it |
| Secrets | KATMAN_KEY and your OpenRouter key are read from the environment, never saved or printed |
| Telemetry | None |
| Consumer chat apps | Never automated |
What Katman reads
Katman reads files under your project root so it can understand your framework, routes, head tags and content. It skips:
node_modules,.gitand build output folders;.env*and.dev.vars*files;*.pem,*.keyand*.p12files;- any file with
secretorcredentialin its name.
The project root is the folder you pass as project_root, or KATMAN_PROJECT_ROOT, or the root your MCP client reports, or the current folder, in that order.
What Katman writes
Katman writes only to .katman/ inside your project: research, scans, audits, visibility runs, the plan, a report and a dated log. The folder never contains secrets, so it’s safe to commit. The full file list is in Getting started.
Two tools can write elsewhere, and only when you pass write: true:
katman_generatewrites the file you asked for, such asrobots.txtorllms.txt;katman_setup_monitoringwrites.github/workflows/katman.yml.
Neither replaces an existing file unless you also pass overwrite: true. Everything else in your code is changed by your AI coding tool, under that tool’s own approval settings, not by Katman.
Katman also keeps one file outside your project: ~/.katman/license.json, the answer of the last plan check, stored under the SHA-256 hash of your key (never the key itself).
What Katman sends over the network
Each call happens only when you, or your agent, call the tool that needs it.
| Destination | Tool | When |
|---|---|---|
| Your own site’s URLs | katman_audit_site, katman_lint_content with a URL, katman_indexnow (to check your key file) |
Each time you audit or verify |
openrouter.ai |
katman_visibility_run; one small judge call in katman_manual_check if an OpenRouter key is set |
Only with your key, and paid runs only after a dry-run estimate |
api.indexnow.org |
katman_indexnow |
Only with dry_run: false |
suggestqueries.google.com |
katman_keywords |
Throttled, at most 40 requests per call |
katman.pro (plan check) |
Every tool (katman_account only when a key is set) |
At most once a day |
katman.pro (sync) |
katman_sync |
Only with dry_run: false |
Installing or starting Katman with npx also downloads the package from the npm registry. That’s npm, not Katman.
What goes to katman.pro
Every tool except katman_account needs KATMAN_KEY. With the key, Katman contacts katman.pro for two things, and nothing else:
- The plan check. Before a tool runs, Katman needs to know your plan, so it sends your key and the MCP version to katman.pro, at most once a day. No tool names, no project data. The answer (your plan, when Audit Week ends if you’re on it, and the features the key unlocks) is cached on your machine. If katman.pro can’t be reached, the tools keep working for 7 days after the last successful check; Audit Week never runs past its end date.
katman_sync(Pro), only when you call it withdry_run: false. The dry run, which is the default, shows the exact JSON first. The summary contains gate pass counts, visibility rates by assistant and language, plan progress, the top 10 issue titles, dates and the Katman version, and nothing else.
Code, file contents, AI answers, your questions, your prompts and your OpenRouter key never leave your machine for katman.pro. The key is sent only in the body of an HTTPS request to katman.pro, redirects aren’t followed, and a value that doesn’t look like a Katman key is never sent. What katman.pro stores about your account is in the privacy policy.
Your keys
KATMAN_KEY(km_live_…) is needed for every tool exceptkatman_account. After you buy Audit Week or Pro, create it in your account at katman.pro/app → MCP, and revoke it there if it leaks.OPENROUTER_API_KEY(orKATMAN_OPENROUTER_API_KEY) is only for visibility runs and goes only to OpenRouter, as the authorisation for your own calls.
Katman reads both from the environment your client starts it with. It never writes them to disk, never prints them, and removes them from error messages. How to set them up per client is in Getting started.
No telemetry
Katman doesn’t send usage data. We don’t know which sites you audit, what the audits find or which tools you call, and the plan check carries no project data. If a future version changes anything that talks to katman.pro, it will be listed here first.
Why Katman doesn’t automate the chat apps
Katman doesn’t drive ChatGPT, Claude or Perplexity’s web apps with a headless browser, for three reasons:
- Their terms forbid it. OpenAI’s terms of use prohibit automatically or programmatically extracting data or output, and Anthropic’s, Perplexity’s and Google’s consumer terms have similar rules (OpenAI, Anthropic, Perplexity, Google; checked 30 September 2026).
- Accounts get banned.
- It breaks every week, because the apps’ pages change.
Instead, visibility runs ask the providers’ own models through OpenRouter, with live web search. That is a proxy for what the apps show, and we say so in every report. For the answers people actually see in the apps, you ask the questions yourself, logged out, and paste the answers into katman_manual_check. Both methods are explained in Visibility runs.
Tool hints for your client
Read-only tools set readOnlyHint: true, tools that use the network set openWorldHint: true, and no tool is marked destructive. These are hints: your client may still ask you to approve each call, and you can keep that setting on.
Your AI coding tool is separate
Katman runs inside your coding tool, but what that tool sends to its own model provider, such as your code and your prompts, is governed by the tool’s own settings and terms, not by Katman. What katman.pro itself collects is in the privacy policy.
Frequently asked questions
Can Katman read my .env file?
No. Katman never opens .env or .dev.vars files, .pem, .key or .p12 files, or any file with “secret” or “credential” in its name.
Does Katman send my code anywhere?
No. Katman reads your code locally and sends none of it over the network; audits fetch your public site, visibility runs send only your questions to OpenRouter, and katman_sync sends aggregate numbers, never code or file contents.
What does Katman send to katman.pro?
Two things, and nothing else: your key and the MCP version, at most once a day, to check your plan; and, only when you call katman_sync with dry_run: false, a project summary of gate counts, visibility rates, plan progress, issue titles and dates.
Does Katman collect usage data?
No. There is no telemetry: no tool names, no project data and no usage counts are sent with the plan check.
Can Katman change my code?
Only by writing a generated file when you call katman_generate or katman_setup_monitoring with write: true. Everything else in your code is changed by your AI coding tool, under its own approval settings.
Why can’t Katman check the ChatGPT app automatically?
Because the consumer apps’ terms forbid automated extraction, accounts get banned, and the pages change often. Katman uses the providers’ models through OpenRouter and records app answers that you paste in with katman_manual_check.