docs

Command line

Run Hugin headless and script it — the commands you reach for on a box with no screen.

Everything in the desktop app is also driveable from the command line, which is how you run Hugin on a VPS, in a container, or in a pipeline. Run hugin --help for the full tree; these are the ones you reach for. --headless and --verbose are global — they work before or after the subcommand.

Start and control

# Run headless: proxy on 8080, control API on 8081
hugin --headless start --port 8080 --api-port 8081

# Start and also expose the MCP server connected to the API
hugin --headless start --mcp

hugin setup             # guided first-run wizard: ports, CA + trust, licence, MCP
hugin status            # is the proxy up?
hugin doctor            # health + security diagnostics (DB, binary hash, DNS, VPN)
hugin init              # write a default config file

Certificate

hugin ca export         # write the CA cert so a browser or device can trust it
hugin ca trust          # install the CA into the system trust store
hugin ca untrust        # remove it again

Flows and WebSocket

# List captured flows — same HTTPQL the UI filter bar speaks
hugin flows --query 'method:POST status:>400 host:*.example.com'
hugin flows --preset my-filter --flagged --limit 50 --format json
hugin flow <id>                 # full detail for one flow

hugin ws list                   # WebSocket connections
hugin ws messages <id>          # frames for one connection
hugin ws export <id>            # dump them

Access control and OOB

# Query access-control findings (Endpointer + Authorize feed these)
hugin bac findings              # also: signals, corpus, export, purge

# Self-hosted out-of-band callback server
hugin oastify-setup --domain oob.example.com --ip 203.0.113.10   # deployment guide
hugin oastify connect --domain oob.example.com                   # talk to a live server

Recon

# Open a URL in Hugin's Chrome-fingerprinted visual browser
hugin browse https://target.example --width 1280 --height 800

Extending

hugin scanner install <module>  # Synaps WASM module — also list / update / remove
hugin plugin install <path>     # Lua plugin — also list / remove

AI agents

# Speak MCP over stdio so an agent can drive Hugin
hugin mcp

Team

# Run a shared headless instance your team remotes into (binds 0.0.0.0, token auth)
hugin serve --port 8080 --api-port 8081
hugin token create              # mint an access token — also list / revoke

This is the shared-instance model. For the end-to-end encrypted sync where each member runs their own Hugin, see team collaboration.

Maintenance

hugin update                    # update to the latest release (--check to only check)
hugin verify <file>             # verify a release binary's Ed25519 signature
hugin config show               # print the config path and a summary
hugin account show              # licence status — also set / clear
hugin migrate-home <dir>        # move HUGIN_HOME to a new absolute path

The headless API on 8081 is the same surface the desktop app and an MCP agent drive. Anything you can click, you can script.

A headless Hugin on a server is still an intercepting proxy with a CA key, and hugin serve binds 0.0.0.0. Lock down who can reach the control port, keep token auth on, and only test what you are authorised to.

Database integrity

hugin verify-db                          # check default DB (~/.config/hugin/hugin.db)
hugin verify-db --db /path/to/hugin.db   # check a specific file

Verifies SQLite integrity, schema version, and constraint indexes. Exits non-zero if the database is corrupt, the schema is stale, or a required index is missing. Run this if flows or findings go missing or after a hard crash.

FlagDescription
--db -dPath to the database file (defaults to ~/.config/hugin/hugin.db)

MCP tool plugins

Dynamic MCP tool plugins (.dylib on macOS, .so on Linux) extend the MCP server with compiled tool modules loaded at runtime.

hugin plugin mcp list                    # show loaded MCP plugins + their tools
hugin plugin mcp install ./my-tools.dylib  # install a plugin
hugin plugin mcp remove my-tools           # remove by name or filename
hugin plugin mcp dir                      # show plugin directory + contents
SubcommandDescription
listList loaded MCP tool plugins and their exported tools
install <path>Copy a .dylib/.so to the plugin directory
remove <name>Remove a plugin by name or filename
dirShow the plugin directory path and its contents

Full Oastify reference

See Oastify CLI for every hugin oastify subcommand (connect, generate, interactions, native OAST server, and more).

Full QA harness reference

See QA harness CLI for every hugin qa subcommand (walkthrough, wiring-audit, runtime-traversal, e2e, design-audit).

Last updated 2026-06-10.