Developer portal

One API call per consequential action.

Install the SDK, admit an entity, grant a delegation, make a decision, download an Evidence Pack™. Five steps from npm install to a signed pack.

Recent decisions

Demo data

You learn: What KYE™ decides for each agent action, why (reason code), and who must act. You can: Replay the feed; approve or decline the held decision.

  1. KYE™ policy decision point Accounts-payable agentpayments.transferAllowed

    Accounts-payable agent pays a supplier invoice

    permission_granted

    Pay €412.90 to Paperhouse Supplies (demo), invoice INV-2026-0917

    In-appWebhook

    • accounts_payable.settle
    • kye_decide
  2. KYE™ policy decision point Procurement agentpurchase_order.createNeeds approval

    Procurement agent orders above its approval threshold

    approval_threshold_breach

    Order 40 pallets of packaging film from Kilnworks Supplies (demo), £18,400

    App pushIn-appWebhook

    • procurement.replenish
    • kye_decide
  3. KYE™ policy decision point Clinical summarisation agentrecord.readDenied

    Clinical summarisation agent asks to read records for marketing

    permission_missing

    Read 1,200 patient records to build a marketing list (demo)

    In-appWebhook

    • marketing.outreach
    • kye_purpose_admit
  4. KYE™ policy decision point HR operations agenthr.record.updateDenied

    HR operations agent acts on a revoked delegation

    delegation_revoked

    Change a staff member's contracted hours (demo)

    In-appWebhook

    • hr.contract.administer
    • kye_authority_check
  5. KYE™ policy decision point Research and drafting agentdocument.draftAllowed

    Drafting agent prepares a disclosure letter, with redaction

    permission_granted

    Draft a disclosure letter for matter M-2207 (demo)

    In-appWebhook

    • legal.matter_support
    • kye_decide
  6. KYE™ policy decision point Credit decisioning agentcredit.line.approveDenied

    Credit agent acts outside its jurisdiction

    jurisdiction_unsupported

    Approve a £4,200 credit line for an applicant in the US (demo)

    In-appWebhook

    • lending.adjudicate
    • kye_decide
How this widget is built
Demonstrates
Decision feed
Components
  • Policy decision point (kye_decide)
  • Decision records (kye.decision.record.v1)
  • Approval routing (dual control)
  • Evidence packs
Flow
Each agent action is decided against its chain of authority; approvals go to the delegate who holds the threshold; every outcome is sealed. Architecture diagram
Used on
  • /examples/: On the examples page, with the rest of its scenario.
  • /developers/: The developer portal: what every call returns.
  • /governed-ui/: GovernedUI™: the decisions it shows.
  • /mcp/: The MCP server: the decisions behind its tools.
  • /platform/: The platform: decisions with their chains of authority.
  • /terminal/: The terminal: every decision, replayable.

Install

Pick a language. One command.

# TypeScript / Node
npm install @kye/sdk

# Python
pip install kye-sdk

# Go
go get github.com/kye-protocol/sdk-go

# Run the reference Gateway locally (Cloudflare-native)
cd internal && npx wrangler dev

Try it without installing anything — in-browser sandbox sends real /v1/runtime/authorize calls to a hosted Gateway and shows the signed Decision Map™.

Quickstart · ship in 5 minutes

Three SDKs. One authorize call.

Pick a language. Drop in the SDK. Ask the gateway whether the action is allowed. Every response is a verifiable decision your auditors can replay.

// npm i @kye/sdk
import { KyeClient } from "@kye/sdk";

const kye = new KyeClient({ baseUrl: "https://gw.example/v1" });

const decision = await kye.authorize({
  actor:               { entity_id: "kye:ent:acme:ai_agent:01J..." },
  acting_on_behalf_of: { delegation_id: "kye:del:acme:01J..." },
  action:              "payment.transfer",
  // Declare WHAT the action does + classify its risk — the Action
  // Admissibility inputs. Authorised does not imply safe; risk drives
  // the dynamic authority gate (oversight mode).
  action_declaration:  { effect_class: "financial", reversibility: "irreversible", rollback_available: false },
  action_risk_classification: { risk_tier: "high", required_oversight_mode: "two_person" },
});

if (decision.decision !== "allow_with_constraints") throw new Error(decision.reasons.join(","));

// → { decision: "allow_with_constraints", obligations: ["audit.emit"],
//     stop_conditions: ["actor.stop_signal","delegation.revoked",...] }
# pip install kye-sdk
from kye_sdk import KyeClient

kye = KyeClient(base_url="https://gw.example/v1")

decision = kye.authorize({
    "actor":               {"entity_id": "kye:ent:acme:ai_agent:01J..."},
    "acting_on_behalf_of": {"delegation_id": "kye:del:acme:01J..."},
    "action":              "payment.transfer",
    # Action Admissibility inputs — declare the effect + classify risk
    "action_declaration":  {"effect_class": "financial", "reversibility": "irreversible"},
    "action_risk_classification": {"risk_tier": "high", "required_oversight_mode": "two_person"},
})

assert decision["decision"] == "allow_with_constraints", decision["reasons"]
// go get github.com/kye-protocol/sdk-go
package main

import (
    "context"
    "github.com/kye-protocol/sdk-go/pkg/kye"
)

func main() {
    c := kye.NewClient("https://gw.example")
    d, err := c.Authorize(context.Background(), kye.AuthorizeRequest{
        Action: "document.render",
        Actor:  kye.Actor{EntityID: "kye:ent:acme:ai_agent:01J..."},
    })
    if err != nil { panic(err) }
    // d.Decision == "allow_with_constraints"
    _ = d
}
# Plain HTTP — no SDK required
curl -X POST https://gw.example/v1/runtime/authorize \
  -H 'content-type: application/json' \
  -H 'idempotency-key: 8c4a-...' \
  -d '{
    "actor":               { "entity_id": "kye:ent:acme:ai_agent:01J..." },
    "acting_on_behalf_of": { "delegation_id": "kye:del:acme:01J..." },
    "action":              "payment.transfer",
    "action_declaration":  { "effect_class": "financial", "reversibility": "irreversible" },
    "action_risk_classification": { "risk_tier": "high", "required_oversight_mode": "two_person" }
  }'

# → { "decision":"allow_with_constraints", "reasons":["delegation_active","scope_match"], ... }

Subscribe to signed signals in 10 minutes.

KYE Protocol™ is event-driven. The KYE™ Signal Bus™ emits signed, replayable events for every authority, decision, recovery and evidence-pack lifecycle. Build a verifier:

  1. Install the SDK — npm i @kye/sdk · pip install kye-sdk · go get github.com/kye-protocol/sdk-go
  2. Stand up a POST receiver that accepts the canonical JSON envelope (schema: https://kyeprotocol.com/schemas/signal.json).
  3. On receive: verifyWebhook(envelope, headers) against the publisher's published JWKS. Multiple signing-suite bindings are supported per the conformance pack.
  4. Deduplicate by event_id using the SDK's idempotency helper or your store. Replays carry the same id.
  5. Switch on event_type — kye.authority.revoked, kye.decision.requires_approval, kye.capability.quarantined, kye.evidence_pack.generated, etc. (see 24 event families).
  6. Ack with 2xx within the publisher's timeout. Anything else → retry with exponential backoff → eventual DLQ.
  7. Subscribe via POST /v1/webhook-endpoints with your URL + filter expression + retry policy. Test via :test.

Open contract: envelope schema, every event-family schema, verifier SDK, reference Gateway webhook handler + retry loop + DLQ + replay endpoint, conformance test vectors.

Get an API key and make one call.

Build 12 pages

  • Build with KYE™Build authority-aware apps with KYE Protocol™. Runtime Authority API, three SDKs (TypeScript / Python / Go), KYE™ MCP Server, Connector Hub™, signed…
  • Load KYE™ as an agent tool in one fileThe KYE™ Agent Tool Pack™ ships every KYE Protocol™ API as a signed, single-file .kye-tool — agent-loadable in seconds, with 60-80% fewer tokens than the…
  • SandboxIn-browser KYE Protocol™ sandbox. Build an /v1/runtime/authorize request, see the assembled JSON, copy the curl, see a deterministic stub Decision Map™…
  • Documentation hubKYE Protocol™ documentation: vocabulary, ID format, schemas, SDKs, conformance pack, sector profiles, whitepaper. Curated reading order.
  • Developer QuickstartYour first governed decision in minutes: get a sandbox key, send one authority-decision request to KYE Protocol™, read the verdict + Evidence Pack™ reference…
  • Build on KYE™ / KYE™ InsideBuild on KYE™. The black-box authority + evidence engine you embed via SDK/API so your branded app can prove who authorised every consequential action…
  • Governed.shgoverned.sh is the KYE™ developer front door: install governed agents and apps into your stack off the shelf, or build your own with the Agent Dev Kit™. Every…
  • KYE™ DevelopersTypeScript. Python. Go. Same names.

API reference 22 pages

  • DictionariesDictionaries are versioned lists of canonical terms — definitions, categories, severities, control mappings
  • ManifestsEvery installable / verifiable / billable unit in KYE™ is a signed manifest. Connectors, widgets, SKUs, rule packs, sector packs, MCP tools, proof bundles…
  • SchemasKYE™ schemas — JSON Schema 2020-12 contracts that validate every payload at runtime. Step 4 of the canonical 8-step KYE™ stack
  • VocabularyCanonical KYE Protocol™ vocabulary: entity types, action types, decision codes, reason codes, capability kinds, side-effect levels, data classes, signal…
  • Event-driven by constitutionKYE™ is the only AI-governance protocol that proves it isn't post-facto. Every privileged action emits a signed evidence envelope at the moment of the…
  • Consultant Program™ APIKYE Protocol™ — Consultant Program™ API: 37 operations from consultant-programme.openapi.yaml, a published KYE Protocol™ OpenAPI contract.
  • Example payloadsIllustrative JSON payloads that show the shape of KYE™ artefacts using public vocabulary: an entity, a delegation, a scope, a policy decision and a runtime…
  • KYE Protocol™ Admin APIKYE Protocol™ Admin API: 188 operations from admin.yaml, a published KYE Protocol™ OpenAPI contract.

Interfaces and connectors 3 pages

  • Connector Hub™The KYE™ Connector Hub™. Plug KYE Protocol™ into payment gateways, internet/mobile payment gateways, checkout, shopping carts, wallets, MCP servers, agent…
  • KYE™ Tool & MCP Authority Register™The KYE™ Tool & MCP Authority Register™ is the tenant-scoped, signed register declaring every tool and MCP server an agent may invoke. The KYE™ Tool Authority…
  • KYE™ CKAN Connector™Govern CKAN datasets, resources, harvests, metadata changes and publication workflows with KYE Protocol™ authority, purpose, evidence and replay

Libraries and ecosystem 2 pages

  • Discoverability ProfileKYE™ Discoverability Profile™ turns the authority graph into a policy-filtered discovery layer for entities, agents, capabilities, delegations, decisions…
  • EcosystemThe KYE Protocol™ ecosystem: Connector Hub™ integrates, Connector Profiles™ make authority portable across sectors, App Store productises, Plugin…

KYE™ Open Source 12 pages

  • Software Constitution StandardLanguage-agnostic, provider-agnostic standard for enforcing your project's design principles at CI time. Apache 2.0. KYE Protocol™ is the reference…
  • AdoptersCodebases conforming to the software/constitution™ open standard. Verdicts at L0–L4 via SCCT. Apache 2.0.
  • Agent Dev Kit templatesSelf-governing-by-default scaffolds — every template emits the §0.3 governance event family out of the box. They extend the canonical hello / kyc / payment set…
  • ContributingKYE Protocol™ is an open protocol with private operational engines. The OSS surface — SDKs, verifiers, schemas, fixtures — is community-driven under Apache…
  • Developer playbooksProvider-agnostic, patent-safe patterns. Each playbook is pure pattern plus links to public schemas and examples — zero mechanism content. Read one, then…
  • Framework adaptersThin wrappers so popular agent / RAG / data frameworks emit the KYE™ §0.3 governance + evidence envelopes for free. Each adapter reuses the SAME envelope shape…
  • Getting startedInstall @kye/shadow-mode-sdk, register an observed action, generate an Evidence Pack, verify it offline. Pure local mode — no API key required.
  • LicenseAll KYE™ OSS packages ship under the Apache License 2.0, with a KYE-specific Notice covering trademarks. The full Apache 2.0 text is reproduced below, followed…

Tools 9 pages

  • KYE™ Authority Finality™ DiagnosticThe Authority Finality™ Diagnostic — 24 questions × 6 lenses across your agentic AI authority posture. Free pyramid-summary score in your IDE; free signed…
  • Free toolsFree, hands-on KYE Protocol™ tools you can use in your browser right now — the sandbox, the Authority Finality™ diagnostic, the Risk Profiler, the Evidence…
  • Interactive demosInteractive demos for KYE Protocol™: decision flow, cascade visualizer, URN parser, trust graph, dashboard counters, and vocabulary browser.
  • End-to-end demoOne-click end-to-end demo of the KYE Protocol™ runtime — Gateway → PDP → Edge Arbiter → MCP Server
  • Interactive examplesEvery agent action decided with its chain of authority: the decision feed, two chains of authority, the delegation chain, Purpose Permission™ and its twelve…
  • KYE Protocol™ LabList governed agents, read a delegation's scope, evaluate an action, replay it safely, get a refusal and read the hash-chained audit events, in a simulation…
  • KYE Protocol™ TerminalAn interactive demo of the KYE Protocol™ terminal: an agent requests an action; identity, on-behalf-of, authority, scope, state and audit are checked; the…
  • KYE™ Widgets™Embeddable KYE™ Widgets™. Filter by stakeholder (Developer / Buyer / Auditor / Regulator / Consultant / Partner / Civil Society) and category