Command line
Run Hugin headless and script it — the commands you reach for on a box with no screen.
Everything in the desktop app is also driveable from the command line, which is
how you run Hugin on a VPS, in a container, or in a pipeline. Run hugin --help
for the full tree; these are the ones you reach for. --headless and --verbose
are global — they work before or after the subcommand.
Start and control
# Run headless: proxy on 8080, control API on 8081
hugin --headless start --port 8080 --api-port 8081
# Start and also expose the MCP server connected to the API
hugin --headless start --mcp
hugin setup # guided first-run wizard: ports, CA + trust, licence, MCP
hugin status # is the proxy up?
hugin doctor # health + security diagnostics (DB, binary hash, DNS, VPN)
hugin init # write a default config file
Certificate
hugin ca export # write the CA cert so a browser or device can trust it
hugin ca trust # install the CA into the system trust store
hugin ca untrust # remove it again
Flows and WebSocket
# List captured flows — same HTTPQL the UI filter bar speaks
hugin flows --query 'method:POST status:>400 host:*.example.com'
hugin flows --preset my-filter --flagged --limit 50 --format json
hugin flow <id> # full detail for one flow
hugin ws list # WebSocket connections
hugin ws messages <id> # frames for one connection
hugin ws export <id> # dump them
Access control and OOB
# Query access-control findings (Endpointer + Authorize feed these)
hugin bac findings # also: signals, corpus, export, purge
# Self-hosted out-of-band callback server
hugin oastify-setup --domain oob.example.com --ip 203.0.113.10 # deployment guide
hugin oastify connect --domain oob.example.com # talk to a live server
Recon
# Open a URL in Hugin's Chrome-fingerprinted visual browser
hugin browse https://target.example --width 1280 --height 800
Extending
hugin scanner install <module> # Synaps WASM module — also list / update / remove
hugin plugin install <path> # Lua plugin — also list / remove
AI agents
# Speak MCP over stdio so an agent can drive Hugin
hugin mcp
Team
# Run a shared headless instance your team remotes into (binds 0.0.0.0, token auth)
hugin serve --port 8080 --api-port 8081
hugin token create # mint an access token — also list / revoke
This is the shared-instance model. For the end-to-end encrypted sync where each member runs their own Hugin, see team collaboration.
Maintenance
hugin update # update to the latest release (--check to only check)
hugin verify <file> # verify a release binary's Ed25519 signature
hugin config show # print the config path and a summary
hugin account show # licence status — also set / clear
hugin migrate-home <dir> # move HUGIN_HOME to a new absolute path
The headless API on 8081 is the same surface the desktop app and an
MCP agent drive. Anything you can click, you can script.
A headless Hugin on a server is still an intercepting proxy with a CA key, and
hugin serve binds 0.0.0.0. Lock down who can reach the control port, keep token
auth on, and only test what you are authorised to.
Database integrity
hugin verify-db # check default DB (~/.config/hugin/hugin.db)
hugin verify-db --db /path/to/hugin.db # check a specific file
Verifies SQLite integrity, schema version, and constraint indexes. Exits non-zero if the database is corrupt, the schema is stale, or a required index is missing. Run this if flows or findings go missing or after a hard crash.
| Flag | Description |
|---|---|
--db -d | Path to the database file (defaults to ~/.config/hugin/hugin.db) |
MCP tool plugins
Dynamic MCP tool plugins (.dylib on macOS, .so on Linux) extend the
MCP server with compiled tool modules loaded at runtime.
hugin plugin mcp list # show loaded MCP plugins + their tools
hugin plugin mcp install ./my-tools.dylib # install a plugin
hugin plugin mcp remove my-tools # remove by name or filename
hugin plugin mcp dir # show plugin directory + contents
| Subcommand | Description |
|---|---|
list | List loaded MCP tool plugins and their exported tools |
install <path> | Copy a .dylib/.so to the plugin directory |
remove <name> | Remove a plugin by name or filename |
dir | Show the plugin directory path and its contents |
Full Oastify reference
See Oastify CLI for every hugin oastify subcommand (connect,
generate, interactions, native OAST server, and more).
Full QA harness reference
See QA harness CLI for every hugin qa subcommand (walkthrough,
wiring-audit, runtime-traversal, e2e, design-audit).