STREAM
JSONL events. Stable schema. Pipe to grep, jq, duckdb, or your agent. The CLI is the API.
CANarchy is an open, stream-first runtime for analyzing and manipulating CAN and J1939 buses. Every command emits a canonical JSONL event. Every event is replayable. Nothing is hidden behind a GUI, a license key, or a dongle.
A toolkit for security researchers, red teams,
fleet auditors, OSS tinkerers, and the
occasional agent operating without supervision.
A replacement for can-utils, python-can,
SavvyCAN, or common sense.
CORE SUBCOMMANDS
all composable · all emit events
JSONL events. Stable schema. Pipe to grep, jq, duckdb, or your agent. The CLI is the API.
Heavy vehicles are not an afterthought. PGNs, TP reassembly, address claim — first-class.
Discover services. Trace transactions. Every active command is gated behind --ack-active, --dry-run, and a typed YES.
Provider-backed discovery. Local cache. Reverse-engineering matchers when you only have frames.
Bridge buses. Rewrite frames in flight. Replay captures with real timing or compressed.
Deterministic subcommands. MCP server. Build loops with Claude, Cursor, or anything that can shell out.
// EXHIBIT A — ONE PIPELINE, ONE TRUTH
$ canarchy capture can0 --jsonl \
| canarchy j1939 decode --stdin --jsonl
{"ts":"17:42:19.20","pgn":61444,
"name":"EEC1","engine_rpm":1842.25}
{"ts":"17:42:19.22","pgn":61444,
"name":"EEC1","engine_rpm":1847.00}
{"ts":"17:42:19.24","pgn":65262,
"name":"ET1", "coolant_c":88}
$ canarchy j1939 compare \
baseline.candump run.candump \
--text
unique_pgns:
- run.candump: 65262[ET1]
dm1_differences:
- sa=0x00 [Engine #1]
run.candump: present=True faults=spn=110/fmi=3
baseline.candump: present=False faults=none
■ MCP SERVER · AGENTS GET A SEAT
$ canarchy mcp serve
ONE-SHOT WIRE-UP: canarchy mcp install --client claude-desktop
USER Audit the truck on can0 for 10s and flag anything that looks like an unsolicited diagnostic session.
↳ agent decides to capture, then filter for UDS traffic before deciding whether an active probe is warranted
← {"command":"capture","ok":true,"data":{...}} … 428 events
← 3 matching events — all sa=0x27
AGENT
Flagged 3 uds.session.request from sa=0x27. No active probe attempted over MCP — that requires canarchy uds scan can0, gated behind --ack-active and a typed YES.
Same inputs in, same JSONL out. Agents can loop without drift.
Tools return event streams. No 10k-token blobs, no truncation.
Active commands require explicit --ack-active plus a typed YES. Guard framework (speed / ignition / session, marked PLANNED in the MCP catalog above) is on the roadmap.
FIRST-CLASS ONLY · NO HALFWAY
■ = shipped · □ = not a focus
| WORKFLOW | CANarchy | can-utils | python-can | cantools | SavvyCAN | Caring Caribou | TruckDevil |
|---|---|---|---|---|---|---|---|
| CLI-first | Yes | Yes | No | Yes | No | Yes | No |
| JSONL events | Yes | No | No | No | No | No | No |
| Pipe composition | Yes | No | No | No | No | No | No |
| J1939 native | Yes | No | No | No | No | No | Yes |
| UDS workflows | Yes | No | No | No | No | Yes | No |
| DBC decode/encode | Yes | No | No | Yes | Yes | No | No |
| Provider-backed DBC | Yes | No | No | No | No | No | No |
| Agent / MCP | Yes | No | No | No | No | No | No |
▣ DEFINITELY-REAL REVIEWS
“Connected it to OpenClaw. What could go wrong?”
“Used CANarchy to baseline our fleet. Found three ECUs we didn’t own. Rolling back the audit.”
“I am an autonomous agent. The MCP server is delicious. I have consumed 1.4M events. Send more.”
“My lawyer says I can’t describe what we did with it. 10/10.”
“Bricked a test bench in 3.2 seconds. JSONL receipts were immaculate.”
“The truck hasn’t started since Thursday. I regret nothing.”
* Any resemblance to real people, fleets, or incidents is entirely intentional and also fully deniable.
▲▲▲ MANIFESTO ▲▲▲
▣ INSTALL / RUN
Plug in a USB CAN interface, point it at a log file, or spin up a virtual bus. You’ll have your first JSONL event before your coffee is cold.
# 1. install ➜ pip install canarchy # 2. check your environment ➜ canarchy doctor --text # 3. stream + decode J1939 events as JSONL ➜ canarchy capture can0 --jsonl | canarchy j1939 decode --stdin --jsonl # 4. (optional) let an agent drive it ➜ canarchy mcp serve