Skip to main content
Sign in to Arbor CloudSign in

Frequently asked questions18 answers

What Arbor can and can’t tell you.

How the local engine works and what it keeps, what receipts and the Claude Code hook change, what Arbor Cloud asks of GitHub and costs, and how to reach us.

Each answer has its own link. Share it and the answer opens for the reader.

01 · 6 questions

The engine

What it answers, what it sends and where its output can go.

What question does Arbor answer?

What else a change can reach. Arbor parses a repository into a graph of functions, classes, and modules, joined by calls and inheritance; imports help it pick the right definition. It answers who calls a symbol, what it calls, and which path connects two of them, with the file and line of each symbol. arbor diff --base main gives each symbol your branch modifies its own blast radius. See the product overview.

Link to this answer
Does the engine send my code anywhere?

Not by itself. Indexing, graph queries, the MCP bridge, and receipts make no network requests: no telemetry, no update check, no model calls. Git runs locally. Arbor reads diffs and history, and receipts store snapshots in your repository’s .git, but it doesn’t fetch or push. The graph is saved in .arbor/ and holds symbol names, file paths, line numbers, signatures, and docstrings.

Link to this answer
Where can Arbor’s output end up?

With your assistant’s model provider: anything your assistant reads through MCP, the Claude Code hooks, or Arbor commands it runs can reach that provider. On a pull request: an Arbor GitHub Action added to a workflow posts its report as a comment by default, unless you turn its comment input off. On your network: arbor serve --headless listens on every interface and accepts connections from any host. In your repository: v3.0.3 doesn’t add .arbor/ to .gitignore, so git add -A would commit your graph and receipts unless you ignore it yourself.

Link to this answer
Which languages does Arbor understand?

Dedicated Tree-sitter parsers cover Rust, TypeScript and JavaScript, Python, Go, Java, C and C++, C#, and Dart. Kotlin, Swift, Ruby, PHP, and Shell go through a line-based fallback parser that records declarations but not the calls inside them, so callers, callees, and impact for those files are mostly empty. In any language, calls made through dynamic imports or reflection can be missed. Read about language coverage.

Link to this answer
Which coding assistants work with Arbor?

Any MCP client that can launch a local stdio server. The MCP guide has setup steps for Claude Code, Cursor, and VS Code. The bridge exposes 16 tools, from get_map, a ranked outline of the project, to get_blast_radius for the impact of your pending changes. arbor bridge --http adds an HTTP transport, on port 3333 by default, that binds to 127.0.0.1.

Link to this answer
Does the graph prove a change is safe?

No. It shows static relationships worth investigating. Dynamic imports and reflection can hide a call, a call through a subclass instance isn’t yet listed among the base method’s callers, some small targets over-report their impact, and a zero blast radius can mean an unresolved edge rather than no impact. Confidence describes the resolver’s evidence, not the chance that something breaks. Read the known limits and run your tests.

Link to this answer
02 · 2 questions

Receipts and Claude Code

What a receipt records and what the hook adds to your project.

What is an Arbor receipt?

A plain-English account of one coding-agent turn, new in v3.0.3. It lists the files and functions the turn changed, flags changed files it judges outside your request (by matching words), names the pages, API routes, and areas the change can reach, and suggests up to four things to test. Routes come from file-based routers such as Next.js; routes declared in code show up as function names. arbor receipt undo <id> --unasked puts back only the flagged files, from a snapshot git removes after about two weeks. Receipts are computed locally from git and the graph, with no model call, and saved in .arbor/receipts/ with the first 2,000 characters of your prompt, so add .arbor/ to .gitignore. They need git and an indexed project, and today they hook into Claude Code only.

Link to this answer
What does arbor hook claude change in my project?

It adds an Arbor section to CLAUDE.md and hooks to .claude/settings.json. Two hooks record receipts: one when you send a request, one when Claude stops. Others are meant to steer Claude from rg, recursive grep, and find . -name to Arbor queries and to show it an Arbor project map once a day, but in v3.0.3 the blocking hooks don’t block anything; see the receipts guide. It also lets Claude run 13 Arbor commands without asking, including graph queries and arbor receipt list and show; undo still asks. In v3.0.3, back up both files first: a file Arbor can’t read, such as one saved as UTF-16, is replaced.

Link to this answer
03 · 6 questions

Arbor Cloud

What Cloud adds to the engine, what it asks of GitHub, and what it costs.

What does Cloud add to the engine?

Analysis of a pull request on GitHub, saved as a private report. When someone in a workspace asks for a run, Cloud confirms the pull request’s base and head commits with GitHub, checks out the head commit, and builds the graph and blast radius with the engine’s open-source libraries (v3.0.3), in a separate worker process. Then it adds its own entry-point, dependency, and code-pattern checks. The report counts the changed symbols and the code upstream and downstream of them, names the most central changed symbols and the entry points that lead to them, and lists known vulnerabilities from OSV in dependencies pinned in Cargo.lock, package-lock.json and npm-shrinkwrap.json; other lockfiles, such as yarn.lock and pnpm-lock.yaml, are listed as unchecked. It doesn’t run on every pull request or post comments. Read about Cloud.

Link to this answer
What does Cloud need from my GitHub account?

Sign-in asks GitHub for your profile and email address (the read:user and user:email scopes). Repositories connect through Arbor’s GitHub App, and each run gets a fresh token for one repository, with read-only access to contents, metadata, and pull requests. Arbor rechecks your GitHub permission before each run and every time a report opens. Reports keep file paths, symbol names, and counts, not source code. Dependency lookups send OSV only package names, versions, and ecosystems.

Link to this answer
What does Cloud cost?

Your GitHub account starts with 3 completed analyses, free and without a card, shared by every workspace it creates. Then Developer is $19 a month for 50 analyses per billing period, and Team is $79 a month for 250 analyses and up to 5 members. Prices are per workspace and in US dollars. A completed, usable report spends one analysis; failed, canceled or unsupported runs don’t, and there are no automatic overages. Compare plans.

Link to this answer
How do I pay, and can I stop?

A workspace owner picks a plan in the workspace, reviews the price, currency and billing period, and pays in Razorpay’s checkout window; we never see your full card number. Billing recurs monthly until the owner stops renewal from the workspace. The plan then runs to the end of the period already paid for. A refunded or disputed payment ends paid access for that period. The terms have the details.

Link to this answer
I used the previous Cloud. What now?

The first Cloud was a GitHub App that posted blast-radius comments on pull requests. It closed on September 23, 2026. This Cloud is a new service: sign in again to start a workspace. Email support@getarbor.dev with your GitHub username about an earlier account, its data, or billing.

Link to this answer
I joined the waitlist. What now?

You can sign in now. Joining didn’t create an account, so start with Sign in to Arbor Cloud. To have your waitlist email deleted, email support@getarbor.dev from the address you joined with.

Link to this answer
04 · 4 questions

The project

Licensing, program support and how to reach us.

Is Arbor free and open source?

The engine is MIT licensed, free, and needs no account. Arbor itself makes no model calls, so it adds no model charges of its own. Your coding assistant’s charges are separate. Arbor Cloud has a free trial and monthly plans. Compare plans.

Link to this answer
What does startup-program support mean?

Arbor has been accepted into AWS Activate, Microsoft for Startups, and Anthropic’s startup program. The support consists of credits and program benefits. It is not an investment or a product endorsement.

Link to this answer
How do I report an engine bug or a wrong answer?

Open an issue in the GitHub issue tracker with the output of arbor --version, your install channel and operating system, and the exact command with its output. For a missing or extra caller, add a few lines of source that reproduce it and the relationship you expected. Keep private code and credentials out of public issues.

Link to this answer
How do I reach you about anything else?

Email support@getarbor.dev. For a security issue, follow the security reporting steps instead of opening a public issue. Tell us what you were trying to learn about a change and what Arbor said. Please don’t send tokens or private source.

Link to this answer