01
A session is a conversation
Every curio session is a Sudo chat with its own sandbox. /workspace is your configuration as files: endpoints, AI tools, agents, schemas, tasks.
curio · The command line for Curiosity Studio
Claude Code works through curio · click the screen to type a request · Esc gives the keys back
Install / 01
The first run asks for your Studio address, opens the browser to sign you in with any login the workspace supports, SSO included, and drops you into the two panels. It needs a system administrator account.
Install script
The self-contained build for your system, checked against the release and put on your PATH. No .NET needed. Run it again to update.
$ curl -fsSL https://curiosity.sh/install.sh | bash
$ curio
PS> irm https://curiosity.sh/install.ps1 | iex
PS> curio
Installs to ~/.curiosity/bin · read the script
.NET tool
With the .NET SDK installed, curio is a global tool. dotnet tool update keeps it current.
$ dotnet tool install --global Curiosity.Shell
$ curio
Or take the single file for your system from the releases
What it is / 02
01
Every curio session is a Sudo chat with its own sandbox. /workspace is your configuration as files: endpoints, AI tools, agents, schemas, tasks.
02
What you write into /workspace stays in the session, marked in the panel, until a commit is staged and approved.
03
A session opened in curio is listed in the admin dock, and the other way round. Sudo can edit while you watch the panel change.
The loop / 03
F9 opens the changes: every file the session touched, its diff, and the buttons that take it to production. Try it on the laptop above.
In the panel, in the command line, or in your own editor with curio get and curio put.
The changed definitions compile against the workspace before anything is staged.
The same diff and the same commit Sudo stages in the dock, waiting for a person.
The workspace applies it and streams the log. Until then, nothing changed.
Keys / 04
Typing anywhere starts a command. It runs in the sandbox, in the active panel's directory: build, commit, graph, query, uid, tasks and the rest. help lists them.
One shot / 05
Exit codes carry through: the sandbox command's own for run, 77 not signed in, 78 not allowed, 75 conflict, 64 usage. For CI, set CURIOSITY_SERVER and CURIOSITY_TOKEN; nothing is stored.
curio login [--server URL] [--approve|--no-approve]
curio logout | whoami
curio sessions [list | new [name] | use <id|name> | rename <name> | rm | reset | stop]
curio run -- <command line> curio run -f script.sh
curio status | diff
curio commit [show | approve | discard]
curio ls [path] | cat <path> | get <path> [local] | put <local> <path> | rm [-r] <path>
curio upload <files...>
curio skills [list [--all] | search <words> | show <name> | install [folder] [--global]]
Your coding agent / 06
curio is a command line, so every coding agent that can run a shell command can work on your workspace through it. The agent never gets more than a session: its edits wait in Sudo's sandbox until a person approves them.
01 · Claude Code
Reads Sudo's skills, edits the files and runs the build, all as curio commands in a session of its own.
02 · Sudo's sandbox
The change is a file in the session, built against the workspace and staged as a commit, the same one Sudo stages in the dock.
03 · You
On Sudo's review screen in your browser, or in curio when you allowed it to. Then, and only then, the workspace runs it.
Reads the skill where it looks for skills. --global puts it in ~/.claude/skills for every project.
$ curio skills installInstall the skill into a folder of the repository and name it in AGENTS.md, the file Codex reads.
$ curio skills install ./.agentsThe same file, in a folder of your choosing; point the project instructions Vibe reads at it.
$ curio skills install ./.agentsIf it can run a shell command, it can run curio: plain output, exit codes that mean something, and one skill that says how.
$ curio skills show curioTry it on the laptop at the top of the page: the default view is a Claude Code session working through curio.
Approving / 07
Not allowed · the default
Approving opens the commit on Sudo's own review screen and curio waits until you approve or discard it there. The workspace enforces it: a token issued to such a curio is refused by the approve routes, and stays refused when it is renewed.
Allowed
curio commit approve and the Approve button in F9 apply the commit and stream the apply log. The sign in page shows the choice as a checkbox, and that is what decides. Sign in again to change your mind.
Signing in / 08
01
An OAuth loopback flow with PKCE. curio listens on 127.0.0.1, the workspace asks you to confirm, and the code that comes back is worthless without the secret curio kept.
02
Windows Credential Manager, the macOS Keychain or the Secret Service on Linux. Where there is none, a file only you can read.
03
It shows up under Manage, Tokens as curio on user@machine. Revoking it there signs curio out; curio logout revokes it too.
04
A WebSocket to the session carries commands out and every change back: Sudo editing in the dock, a commit staged, an approval in the browser. Behind a strict proxy it falls back to server sent events.
Open a terminal. Sudo is waiting.