Payments & commerce
IPG · MPG · payment gateway · checkout · shopping cart · card-token · wallet · open banking · merchant-risk · chargeback / dispute
Build with KYE™
KYE Protocol™ is not just a specification — it's a build surface. Runtime Authority API, three SDKs, an MCP server, a connector framework, signed webhooks, Decision Maps™, and evidence packs. Add delegated authority, state-aware decisions, and replayable proof to AI agents, payment flows, checkout, wallets, IAM, SIEM, GRC, and enterprise workflows.
You learn: How it works, one stage at a time. You can: Run it end to end.
TypeScript
KYE Protocol™
npm install @kye/sdk
Python
KYE Protocol™
pip install kye-sdk
Go
KYE Protocol™
go get · module path published with the SDK release
Open source
Six surfaces
POST /v1/runtime/authorize — allow / require_approval / require_step_up / quarantine / deny + reason code + obligations + evidence refs.view decision endpoint →SDKsTypeScript, Python, Go. Schema types, validators, decision client, signing helpers, evidence-pack builder, taxonomy resolver, decision-map renderer, webhook verifier.view SDKs →KYE™ MCP ServerExpose KYE™ schemas, decisions, Decision Maps™ and evidence packs to MCP-compatible agents and developer tools — while production enforcement stays in the runtime gateway.explore MCP server →Connector Hub™Plug KYE™ into payment gateways, checkouts, wallets, IAM, policy engines, SIEM, GRC, agent runtimes, KYC/KYB/KYA. One canonical manifest schema; six families.view connector hub →KYE™ Signal Bus™24 event families, 79 well-known event types, canonical envelope, signed deliveries (HTTPS webhook + SSE / WS + Kafka), idempotent + replayable + dead-letter-safe.view event reference →Evidence PacksGenerate signed, replayable proof bundles. Public-key-verifiable offline. Bind decisions, audit chain, control mapping, and OSCAL projection in one artefact.inspect evidence pack →What you can build
These are the products with the strongest pull from regulated buyers right now. Each composes from the surfaces above.
Other strong starters: agent purchasing apps · agent marketplace trust layers · wallet authority consoles · open-banking delegated-authority apps · enterprise service-account authority maps · GRC evidence automation · SIEM authority-signal feeds · certification portals · tool-governance gateways · capability registries · sector profiles for healthcare / custody / telco / federal.
Runtime Authority API
The decision endpoint is the single most important surface. Your app asks; KYE™ answers in milliseconds.
POST /v1/runtime/authorize
{
"actor_entity_id": "kye:entity:agent:shopping_agent_456",
"principal_entity_id": "kye:entity:person:customer_123",
"subject": "kye:capability:payment_action:card_purchase",
"resource": { "merchant_id": "M-7104", "amount": 9999, "currency": "GBP" },
"scope": { "instrument": "kye:card_token:tok_abc..." },
"policy_decision_id": "kye:dec:01HX..."
}
→
{
"decision": "allow_with_constraints",
"reason": "scope_within_attenuated_authority",
"obligations": [ { "type": "audit.emit", ... }, { "type": "redaction.required", ... } ],
"stop_conditions": [ "actor.stop_signal", "delegation.revoked", "scope.attenuated" ],
"evidence_refs": [ "kye:evidence-pack:01HX..." ],
"decision_map_ref": "kye:decision_map:01HX..."
}
Eight decision codes are stable across versions: allow, allow_with_constraints, require_approval, require_step_up, require_human_review, require_recovery, quarantine, deny. Map to your own code-set via the conformance pack.
Three SDKs
npm install @kye/sdkpip install kye-sdkgo get · module path published with the SDK releaseEach SDK ships: schema types · local validators · decision client · signing helpers · evidence-pack builder · taxonomy resolver · metadata classifier · graph traversal client · decision-map renderer · webhook verifier · idempotency helper · replay client.
KYE™ MCP Server
Expose KYE™ schemas, dictionaries, authority checks, Decision Maps™, and evidence packs through a controlled MCP interface — while production enforcement stays in the KYE™ Runtime Gateway™, never in MCP.
The boundary: MCP is a developer / agent integration surface. The Runtime Gateway is the enforcement surface. Don't conflate.
Connector Framework
A canonical connector manifest schema, six connector families, and a hub for discovery.
IPG · MPG · payment gateway · checkout · shopping cart · card-token · wallet · open banking · merchant-risk · chargeback / dispute
MCP · agent runtime · tool gateway · capability registry · model registry · prompt registry · workflow
OAuth/OIDC · SAML · SCIM · SPIFFE/SPIRE · IAM · PAM · passkey · credential issuer
OPA · Cerbos · AWS Cedar · GRC · control mapping · certification · self-audit
SIEM · SOAR · Splunk · Microsoft Sentinel · Datadog · CloudWatch · Kafka · EventBridge · webhook
KYC provider · KYB provider · KYA provider · agent passport · credential verification
What ships today
Every contract below is implementable today — partners and developers integrate without depending on any hosted service.
| Surface | What you get |
|---|---|
| Schemas & dictionaries | Every entity / authority / decision / event / connector-manifest schema; reason codes; taxonomies |
| SDKs | TypeScript / Python / Go — schema types, validators, signing helpers, webhook verifier, evidence-pack builder |
| MCP server | Skeleton + read-only tools + decision tools (gated) |
| Connectors | Manifest schema, conformance tests, sample IPG / checkout / MCP connectors, local test harness |
| Reference runtime | KYE™ Reference Gateway™: PEP middleware, embedded ePDP, conformance runner |
| Conformance | 133 black-box fixtures, test vectors |
Adjacent reading
Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.
Canonical KYE™ surfaces referenced on this page: Authority Graph™ · Evidence Pack™ · KYE™ Conformance Pack™ · KYE Protocol™.