vakt

Configuration

Configure vakt model access, local caching, compute precision, and hardware selection.

Model access

The default model is DOM-0.8B. Request access on Hugging Face, then authenticate using hf auth login or provide HF_TOKEN through your environment.

hf auth login
vakt summon

vakt summon downloads the model before a scan. The default weights are pinned to a specific revision so a model repository update does not silently change scan results. Once downloaded, inference runs locally.

Do not commit Hugging Face tokens to your repository or MCP configuration. In CI, use your platform’s secret store.

Local checkpoints

Pass a compatible local checkpoint to avoid downloading weights during the scan:

vakt patrol . --model /path/to/model.safetensors

The CLI also accepts Hugging Face references and explicit revisions:

vakt summon --model hf:vaktex/dom-oss-0.8b
vakt patrol . --model hf:vaktex/dom-oss-0.8b --revision main

An explicit revision overrides an @revision suffix in --model. Using main opts out of the default pinned revision; use an exact commit for reproducible results. The model must be compatible with the scanner’s engine, not an arbitrary language model.

Cache

Scores are cached by model, precision, and prompt so repeated scans can reuse unchanged results. To move vakt’s cache:

export VAKT_CACHE="$HOME/.vakt"

To scan without reading or writing the score cache:

vakt . --no-cache

This disables the score cache, not the need for model weights.

Hardware

The installer selects a native backend for your platform. The CLI defaults to automatic device selection:

vakt . --device auto
vakt . --device cpu
vakt . --device gpu

Device availability depends on your installed build and hardware. Linux supports CPU execution and CUDA 13 on supported NVIDIA GPUs; Apple Silicon uses Metal. Select multiple GPU indices with:

vakt . --device gpu --devices 0,1

--devices cannot be combined with --device cpu.

Precision and work limits

The default precision is fp32. tf32 and bf16 trade numerical precision for throughput on supporting hardware:

vakt . --precision bf16

Do not assume scores are identical across precisions. Validate your failure threshold using the precision you deploy.

  • --jobs sets parallel walk, parse, and tokenize workers; the default is the number of CPUs.
  • --batch-tokens sets the padded token budget per model batch; default: 4096.
  • --max-file-bytes sets the maximum scanned file size; default: 2097152.

Diagnostics

vakt doctor
vakt version
vakt . --verbose

Use these commands to inspect the installation and backend before troubleshooting a scan. For an access-denied model download, confirm that the token belongs to the Hugging Face account approved for the gated model. For an unavailable device, confirm that your release build matches the machine and backend.

See vakt patrol --help and vakt summon --help for the installed version’s full option lists.

Improve team velocity with
better security and privacy.