Build with KYE™

Build authority-aware apps with KYE™.

KYE Protocol™ is not just a specification — it's a build surface. Runtime Authority API, three SDKs, an MCP server, a connector framework, signed webhooks, Decision Maps™, and evidence packs. Add delegated authority, state-aware decisions, and replayable proof to AI agents, payment flows, checkout, wallets, IAM, SIEM, GRC, and enterprise workflows.

Build with KYE™, stage by stage

Demo data

You learn: How it works, one stage at a time. You can: Run it end to end.

  1. TypeScript

    KYE Protocol™

    npm install @kye/sdk

  2. Python

    KYE Protocol™

    pip install kye-sdk

  3. Go

    KYE Protocol™

    go get · module path published with the SDK release

How this widget is built
Demonstrates
KYE™ runtime
Components
  • The stages this page describes
Flow
Each stage in order, as the page sets it out. Architecture diagram
Used on
  • /build/: On this page, after its opening.

Open source

What you can build

Six high-use starters — and 15 more.

These are the products with the strongest pull from regulated buyers right now. Each composes from the surfaces above.

  • P1KYE™ Checkout Guard™ — for merchants and commerce platforms. Detect agent-backed checkout flows and verify whether the agent is allowed to buy this basket from this merchant using this instrument under the customer's limits. Composes: Runtime API + KYE™ Signal Bus™ + Evidence Packs.
  • P2KYE™ Payment Authority Gateway™ — for banks, issuers, IPGs, MPGs, PSPs, agentic-payment platforms. Verify delegated payment authority before the gateway processes the transaction. Composes: Runtime API + Payments connector + Evidence Packs.
  • P3KYE™ MCP Server — for agent developers and internal AI platforms. Expose KYE™ authority objects, schemas, decisions, and evidence to MCP clients safely. Composes: MCP Server + Read-only tools + Gated decision tools.
  • P4KYE™ CISO Console™ — for security and risk teams. View every agent, credential, capability, delegation, state, and revocation path. Composes: Authority Graph™ + KYE™ Signal Bus™ + Audit chain.
  • P5KYE™ Evidence Viewer™ — for auditors and regulators. Replay decisions, verify evidence packs offline with public keys, map events to controls. Composes: Evidence Packs + OSCAL projection + Decision Maps™.
  • P6KYE™ Partner Toolkit™ — for consultants, audit firms, SIs. Run authority mapping, readiness checks, conformance prep, pilot scoping. Composes: Readiness API + Conformance pack + Decision Maps™.

Other strong starters: agent purchasing apps · agent marketplace trust layers · wallet authority consoles · open-banking delegated-authority apps · enterprise service-account authority maps · GRC evidence automation · SIEM authority-signal feeds · certification portals · tool-governance gateways · capability registries · sector profiles for healthcare / custody / telco / federal.

Runtime Authority API

One call, before the action executes.

The decision endpoint is the single most important surface. Your app asks; KYE™ answers in milliseconds.

POST /v1/runtime/authorize
{
  "actor_entity_id":     "kye:entity:agent:shopping_agent_456",
  "principal_entity_id": "kye:entity:person:customer_123",
  "subject":             "kye:capability:payment_action:card_purchase",
  "resource":            { "merchant_id": "M-7104", "amount": 9999, "currency": "GBP" },
  "scope":               { "instrument": "kye:card_token:tok_abc..." },
  "policy_decision_id":  "kye:dec:01HX..."
}

→
{
  "decision":  "allow_with_constraints",
  "reason":    "scope_within_attenuated_authority",
  "obligations": [ { "type": "audit.emit", ... }, { "type": "redaction.required", ... } ],
  "stop_conditions": [ "actor.stop_signal", "delegation.revoked", "scope.attenuated" ],
  "evidence_refs":   [ "kye:evidence-pack:01HX..." ],
  "decision_map_ref": "kye:decision_map:01HX..."
}

Eight decision codes are stable across versions: allow, allow_with_constraints, require_approval, require_step_up, require_human_review, require_recovery, quarantine, deny. Map to your own code-set via the conformance pack.

Three SDKs

Same surface in TypeScript, Python, and Go.

  • TypeScript — npm install @kye/sdk
  • Python — pip install kye-sdk
  • Go — go get · module path published with the SDK release

Each SDK ships: schema types · local validators · decision client · signing helpers · evidence-pack builder · taxonomy resolver · metadata classifier · graph traversal client · decision-map renderer · webhook verifier · idempotency helper · replay client.

KYE™ MCP Server

Make KYE™ available to MCP-compatible agents.

Expose KYE™ schemas, dictionaries, authority checks, Decision Maps™, and evidence packs through a controlled MCP interface — while production enforcement stays in the KYE™ Runtime Gateway™, never in MCP.

The boundary: MCP is a developer / agent integration surface. The Runtime Gateway is the enforcement surface. Don't conflate.

Connector Framework

Plug KYE™ into the systems you already run.

A canonical connector manifest schema, six connector families, and a hub for discovery.

Payments & commerce

IPG · MPG · payment gateway · checkout · shopping cart · card-token · wallet · open banking · merchant-risk · chargeback / dispute

AI & agent runtime

MCP · agent runtime · tool gateway · capability registry · model registry · prompt registry · workflow

Identity & access

OAuth/OIDC · SAML · SCIM · SPIFFE/SPIRE · IAM · PAM · passkey · credential issuer

Policy & governance

OPA · Cerbos · AWS Cedar · GRC · control mapping · certification · self-audit

Security & observability

SIEM · SOAR · Splunk · Microsoft Sentinel · Datadog · CloudWatch · Kafka · EventBridge · webhook

Verification

KYC provider · KYB provider · KYA provider · agent passport · credential verification

What ships today

Open source

Every contract below is implementable today — partners and developers integrate without depending on any hosted service.

SurfaceWhat you get
Schemas & dictionariesEvery entity / authority / decision / event / connector-manifest schema; reason codes; taxonomies
SDKsTypeScript / Python / Go — schema types, validators, signing helpers, webhook verifier, evidence-pack builder
MCP serverSkeleton + read-only tools + decision tools (gated)
ConnectorsManifest schema, conformance tests, sample IPG / checkout / MCP connectors, local test harness
Reference runtimeKYE™ Reference Gateway™: PEP middleware, embedded ePDP, conformance runner
Conformance133 black-box fixtures, test vectors

Ready to see your AI agents flagged?

Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.

Canonical KYE™ surfaces referenced on this page: Authority Graph™ · Evidence Pack™ · KYE™ Conformance Pack™ · KYE Protocol™.