Developer portal
One API call per consequential action.
Install the SDK, admit an entity, grant a delegation, make a decision, download an Evidence Pack™. Five steps from npm install to a signed pack.
Recent decisions
Demo dataYou learn: What KYE™ decides for each agent action, why (reason code), and who must act. You can: Replay the feed; approve or decline the held decision.
-
Accounts-payable agent pays a supplier invoice
permission_granted
Pay €412.90 to Paperhouse Supplies (demo), invoice INV-2026-0917
In-appWebhook
- accounts_payable.settle
- kye_decide
-
Procurement agent orders above its approval threshold
approval_threshold_breach
Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400
App pushIn-appWebhook
- procurement.replenish
- kye_decide
-
Clinical summarisation agent asks to read records for marketing
permission_missing
Read 1,200 patient records to build a marketing list (demo)
In-appWebhook
- marketing.outreach
- kye_purpose_admit
-
HR operations agent acts on a revoked delegation
delegation_revoked
Change a staff member's contracted hours (demo)
In-appWebhook
- hr.contract.administer
- kye_authority_check
-
Drafting agent prepares a disclosure letter, with redaction
permission_granted
Draft a disclosure letter for matter M-2207 (demo)
In-appWebhook
- legal.matter_support
- kye_decide
-
Credit agent acts outside its jurisdiction
jurisdiction_unsupported
Approve a £4,200 credit line for an applicant in the US (demo)
In-appWebhook
- lending.adjudicate
- kye_decide
How this widget is built
- Demonstrates
- Decision feed
- Components
- Policy decision point (kye_decide)
- Decision records (kye.decision.record.v1)
- Approval routing (dual control)
- Evidence packs
- Flow
- Each agent action is decided against its chain of authority; approvals go to the delegate who holds the threshold; every outcome is sealed. Architecture diagram
- Used on
- /examples/: On the examples page, with the rest of its scenario.
- /developers/: The developer portal: what every call returns.
- /governed-ui/: GovernedUI™: the decisions it shows.
- /mcp/: The MCP server: the decisions behind its tools.
- /platform/: The platform: decisions with their chains of authority.
- /terminal/: The terminal: every decision, replayable.
Quickstart
Install, admit an entity, delegate, decide, download the pack.
5 stepsSDKsTypeScript, Python, Go
npm install @kye/sdk · pip install kye-sdk · go get github.com/kye-protocol/sdk-go
API reference
16 OpenAPI 3.1 contracts, 568 operations, as published.
BrowseSchemasJSON Schemas
JSON Schema 2020-12 with absolute $ids under kyeprotocol.com/schemas.
Conformance
Black-box fixtures any conformant gateway must pass; self-attestation report.
ReadAgentsKYE™ MCP Server
Authority checks and evidence for agents over the Model Context Protocol.
ReadExamplesExample payloads
5 headline payloads from KYE-Protocol/examples, illustrative and non-normative.
See themTryThe lab
The runtime authority API simulated in your browser, with missions.
Open the labOpen sourcePackages
Apache 2.0 SDKs, CC-BY-4.0 vocabulary, no runtime lock-in.
CatalogueInstall
Pick a language. One command.
# TypeScript / Node
npm install @kye/sdk
# Python
pip install kye-sdk
# Go
go get github.com/kye-protocol/sdk-go
# Run the reference Gateway locally (Cloudflare-native)
cd internal && npx wrangler dev
Try it without installing anything — in-browser sandbox sends real /v1/runtime/authorize calls to a hosted Gateway and shows the signed Decision Map™.
Quickstart · ship in 5 minutes
Three SDKs. One authorize call.
Pick a language. Drop in the SDK. Ask the gateway whether the action is allowed. Every response is a verifiable decision your auditors can replay.
// npm i @kye/sdk
import { KyeClient } from "@kye/sdk";
const kye = new KyeClient({ baseUrl: "https://gw.example/v1" });
const decision = await kye.authorize({
actor: { entity_id: "kye:ent:acme:ai_agent:01J..." },
acting_on_behalf_of: { delegation_id: "kye:del:acme:01J..." },
action: "payment.transfer",
// Declare WHAT the action does + classify its risk — the Action
// Admissibility inputs. Authorised does not imply safe; risk drives
// the dynamic authority gate (oversight mode).
action_declaration: { effect_class: "financial", reversibility: "irreversible", rollback_available: false },
action_risk_classification: { risk_tier: "high", required_oversight_mode: "two_person" },
});
if (decision.decision !== "allow_with_constraints") throw new Error(decision.reasons.join(","));
// → { decision: "allow_with_constraints", obligations: ["audit.emit"],
// stop_conditions: ["actor.stop_signal","delegation.revoked",...] }
# pip install kye-sdk
from kye_sdk import KyeClient
kye = KyeClient(base_url="https://gw.example/v1")
decision = kye.authorize({
"actor": {"entity_id": "kye:ent:acme:ai_agent:01J..."},
"acting_on_behalf_of": {"delegation_id": "kye:del:acme:01J..."},
"action": "payment.transfer",
# Action Admissibility inputs — declare the effect + classify risk
"action_declaration": {"effect_class": "financial", "reversibility": "irreversible"},
"action_risk_classification": {"risk_tier": "high", "required_oversight_mode": "two_person"},
})
assert decision["decision"] == "allow_with_constraints", decision["reasons"]
// go get github.com/kye-protocol/sdk-go
package main
import (
"context"
"github.com/kye-protocol/sdk-go/pkg/kye"
)
func main() {
c := kye.NewClient("https://gw.example")
d, err := c.Authorize(context.Background(), kye.AuthorizeRequest{
Action: "document.render",
Actor: kye.Actor{EntityID: "kye:ent:acme:ai_agent:01J..."},
})
if err != nil { panic(err) }
// d.Decision == "allow_with_constraints"
_ = d
}
# Plain HTTP — no SDK required
curl -X POST https://gw.example/v1/runtime/authorize \
-H 'content-type: application/json' \
-H 'idempotency-key: 8c4a-...' \
-d '{
"actor": { "entity_id": "kye:ent:acme:ai_agent:01J..." },
"acting_on_behalf_of": { "delegation_id": "kye:del:acme:01J..." },
"action": "payment.transfer",
"action_declaration": { "effect_class": "financial", "reversibility": "irreversible" },
"action_risk_classification": { "risk_tier": "high", "required_oversight_mode": "two_person" }
}'
# → { "decision":"allow_with_constraints", "reasons":["delegation_active","scope_match"], ... }
Subscribe to signed signals in 10 minutes.
KYE Protocol™ is event-driven. The KYE™ Signal Bus™ emits signed, replayable events for every authority, decision, recovery and evidence-pack lifecycle. Build a verifier:
- Install the SDK —
npm i @kye/sdk·pip install kye-sdk·go get github.com/kye-protocol/sdk-go - Stand up a
POSTreceiver that accepts the canonical JSON envelope (schema:https://kyeprotocol.com/schemas/signal.json). - On receive:
verifyWebhook(envelope, headers)against the publisher's published JWKS. Multiple signing-suite bindings are supported per the conformance pack. - Deduplicate by
event_idusing the SDK's idempotency helper or your store. Replays carry the same id. - Switch on
event_type—kye.authority.revoked,kye.decision.requires_approval,kye.capability.quarantined,kye.evidence_pack.generated, etc. (see 24 event families). - Ack with
2xxwithin the publisher's timeout. Anything else → retry with exponential backoff → eventual DLQ. - Subscribe via
POST /v1/webhook-endpointswith your URL + filter expression + retry policy. Test via:test.
Open contract: envelope schema, every event-family schema, verifier SDK, reference Gateway webhook handler + retry loop + DLQ + replay endpoint, conformance test vectors.
Get an API key and make one call.
Build 12 pages
- Build with KYE™Build authority-aware apps with KYE Protocol™. Runtime Authority API, three SDKs (TypeScript / Python / Go), KYE™ MCP Server, Connector Hub™, signed…
- Load KYE™ as an agent tool in one fileThe KYE™ Agent Tool Pack™ ships every KYE Protocol™ API as a signed, single-file .kye-tool — agent-loadable in seconds, with 60-80% fewer tokens than the…
- SandboxIn-browser KYE Protocol™ sandbox. Build an /v1/runtime/authorize request, see the assembled JSON, copy the curl, see a deterministic stub Decision Map™…
- Documentation hubKYE Protocol™ documentation: vocabulary, ID format, schemas, SDKs, conformance pack, sector profiles, whitepaper. Curated reading order.
- Developer QuickstartYour first governed decision in minutes: get a sandbox key, send one authority-decision request to KYE Protocol™, read the verdict + Evidence Pack™ reference…
- Build on KYE™ / KYE™ InsideBuild on KYE™. The black-box authority + evidence engine you embed via SDK/API so your branded app can prove who authorised every consequential action…
- Governed.shgoverned.sh is the KYE™ developer front door: install governed agents and apps into your stack off the shelf, or build your own with the Agent Dev Kit™. Every…
- KYE™ DevelopersTypeScript. Python. Go. Same names.
API reference 22 pages
- DictionariesDictionaries are versioned lists of canonical terms — definitions, categories, severities, control mappings
- ManifestsEvery installable / verifiable / billable unit in KYE™ is a signed manifest. Connectors, widgets, SKUs, rule packs, sector packs, MCP tools, proof bundles…
- SchemasKYE™ schemas — JSON Schema 2020-12 contracts that validate every payload at runtime. Step 4 of the canonical 8-step KYE™ stack
- VocabularyCanonical KYE Protocol™ vocabulary: entity types, action types, decision codes, reason codes, capability kinds, side-effect levels, data classes, signal…
- Event-driven by constitutionKYE™ is the only AI-governance protocol that proves it isn't post-facto. Every privileged action emits a signed evidence envelope at the moment of the…
- Consultant Program™ APIKYE Protocol™ — Consultant Program™ API: 37 operations from consultant-programme.openapi.yaml, a published KYE Protocol™ OpenAPI contract.
- Example payloadsIllustrative JSON payloads that show the shape of KYE™ artefacts using public vocabulary: an entity, a delegation, a scope, a policy decision and a runtime…
- KYE Protocol™ Admin APIKYE Protocol™ Admin API: 188 operations from admin.yaml, a published KYE Protocol™ OpenAPI contract.
Interfaces and connectors 3 pages
- Connector Hub™The KYE™ Connector Hub™. Plug KYE Protocol™ into payment gateways, internet/mobile payment gateways, checkout, shopping carts, wallets, MCP servers, agent…
- KYE™ Tool & MCP Authority Register™The KYE™ Tool & MCP Authority Register™ is the tenant-scoped, signed register declaring every tool and MCP server an agent may invoke. The KYE™ Tool Authority…
- KYE™ CKAN Connector™Govern CKAN datasets, resources, harvests, metadata changes and publication workflows with KYE Protocol™ authority, purpose, evidence and replay
Libraries and ecosystem 2 pages
- Discoverability ProfileKYE™ Discoverability Profile™ turns the authority graph into a policy-filtered discovery layer for entities, agents, capabilities, delegations, decisions…
- EcosystemThe KYE Protocol™ ecosystem: Connector Hub™ integrates, Connector Profiles™ make authority portable across sectors, App Store productises, Plugin…
KYE™ Open Source 12 pages
- Software Constitution StandardLanguage-agnostic, provider-agnostic standard for enforcing your project's design principles at CI time. Apache 2.0. KYE Protocol™ is the reference…
- AdoptersCodebases conforming to the software/constitution™ open standard. Verdicts at L0–L4 via SCCT. Apache 2.0.
- Agent Dev Kit templatesSelf-governing-by-default scaffolds — every template emits the §0.3 governance event family out of the box. They extend the canonical hello / kyc / payment set…
- ContributingKYE Protocol™ is an open protocol with private operational engines. The OSS surface — SDKs, verifiers, schemas, fixtures — is community-driven under Apache…
- Developer playbooksProvider-agnostic, patent-safe patterns. Each playbook is pure pattern plus links to public schemas and examples — zero mechanism content. Read one, then…
- Framework adaptersThin wrappers so popular agent / RAG / data frameworks emit the KYE™ §0.3 governance + evidence envelopes for free. Each adapter reuses the SAME envelope shape…
- Getting startedInstall @kye/shadow-mode-sdk, register an observed action, generate an Evidence Pack, verify it offline. Pure local mode — no API key required.
- LicenseAll KYE™ OSS packages ship under the Apache License 2.0, with a KYE-specific Notice covering trademarks. The full Apache 2.0 text is reproduced below, followed…
Tools 9 pages
- KYE™ Authority Finality™ DiagnosticThe Authority Finality™ Diagnostic — 24 questions × 6 lenses across your agentic AI authority posture. Free pyramid-summary score in your IDE; free signed…
- Free toolsFree, hands-on KYE Protocol™ tools you can use in your browser right now — the sandbox, the Authority Finality™ diagnostic, the Risk Profiler, the Evidence…
- Interactive demosInteractive demos for KYE Protocol™: decision flow, cascade visualizer, URN parser, trust graph, dashboard counters, and vocabulary browser.
- End-to-end demoOne-click end-to-end demo of the KYE Protocol™ runtime — Gateway → PDP → Edge Arbiter → MCP Server
- Interactive examplesEvery agent action decided with its chain of authority: the decision feed, two chains of authority, the delegation chain, Purpose Permission™ and its twelve…
- KYE Protocol™ LabList governed agents, read a delegation's scope, evaluate an action, replay it safely, get a refusal and read the hash-chained audit events, in a simulation…
- KYE Protocol™ TerminalAn interactive demo of the KYE Protocol™ terminal: an agent requests an action; identity, on-behalf-of, authority, scope, state and audit are checked; the…
- KYE™ Widgets™Embeddable KYE™ Widgets™. Filter by stakeholder (Developer / Buyer / Auditor / Regulator / Consultant / Partner / Civil Society) and category