---
title: "Developer portal | KYE Protocol™"
description: "Build on KYE Protocol™: quickstart, SDKs for TypeScript, Python and Go, the CLI, webhooks, the KYE™ MCP Server and the API reference of 16 OpenAPI contracts (568 operations)."
url: https://kyeprotocol.com/developers/
lang: en
source: "KYE Protocol"
---

> Build on KYE Protocol™: quickstart, SDKs for TypeScript, Python and Go, the CLI, webhooks, the KYE™ MCP Server and the API reference of 16 OpenAPI contracts (568 operations).

Developer portal

# One API call per consequential action.

Install the SDK, admit an entity, grant a delegation, make a decision, download an Evidence Pack™. Five steps from `npm install` to a signed pack.

[Quickstart](https://kyeprotocol.com/developers/quickstart/) [API reference](https://kyeprotocol.com/developers/api/) [Get an API key](https://app.kyeprotocol.com/api-keys.html)

[Start Quickstart Install, admit an entity, delegate, decide, download the pack. 5 steps](https://kyeprotocol.com/developers/quickstart/) [SDKs TypeScript, Python, Go `npm install @kye/sdk` · `pip install kye-sdk` · `go get github.com/kye-protocol/sdk-go` Install](https://kyeprotocol.com/developers/sdks/) [Reference API reference 16 OpenAPI 3.1 contracts, 568 operations, as published. Browse](https://kyeprotocol.com/developers/api/) [Schemas JSON Schemas JSON Schema 2020-12 with absolute `$id` s under kyeprotocol.com/schemas. Read](https://kyeprotocol.com/developers/schemas/) [Conformance Conformance Black-box fixtures any conformant gateway must pass; self-attestation report. Read](https://kyeprotocol.com/developers/conformance/) [Agents KYE™ MCP Server Authority checks and evidence for agents over the Model Context Protocol. Read](https://kyeprotocol.com/mcp/) [Examples Example payloads 5 headline payloads from KYE-Protocol/examples, illustrative and non-normative. See them](https://kyeprotocol.com/developers/examples/) [Try The lab The runtime authority API simulated in your browser, with missions. Open the lab](https://kyeprotocol.com/lab/) [Open source Packages Apache 2.0 SDKs, CC-BY-4.0 vocabulary, no runtime lock-in. Catalogue](https://kyeprotocol.com/oss/)

Install

## Pick a language. One command.

```
# TypeScript / Node
npm install @kye/sdk

# Python
pip install kye-sdk

# Go
go get github.com/kye-protocol/sdk-go

# Run the reference Gateway locally (Cloudflare-native)
cd internal && npx wrangler dev
```

Try it without installing anything — [in-browser sandbox](https://kyeprotocol.com/sandbox/) sends real `/v1/runtime/authorize` calls to a hosted Gateway and shows the signed Decision Map™.

Quickstart · ship in 5 minutes

## Three SDKs. One authorize call.

Pick a language. Drop in the SDK. Ask the gateway whether the action is allowed. Every response is a verifiable decision your auditors can replay.

```
// npm i @kye/sdk
import { KyeClient } from "@kye/sdk";

const kye = new KyeClient({ baseUrl: "https://gw.example/v1" });

const decision = await kye.authorize({
  actor:               { entity_id: "kye:ent:acme:ai_agent:01J..." },
  acting_on_behalf_of: { delegation_id: "kye:del:acme:01J..." },
  action:              "payment.transfer",
  // Declare WHAT the action does + classify its risk — the Action
  // Admissibility inputs. Authorised does not imply safe; risk drives
  // the dynamic authority gate (oversight mode).
  action_declaration:  { effect_class: "financial", reversibility: "irreversible", rollback_available: false },
  action_risk_classification: { risk_tier: "high", required_oversight_mode: "two_person" },
});

if (decision.decision !== "allow_with_constraints") throw new Error(decision.reasons.join(","));

// → { decision: "allow_with_constraints", obligations: ["audit.emit"],
//     stop_conditions: ["actor.stop_signal","delegation.revoked",...] }
```

```
# pip install kye-sdk
from kye_sdk import KyeClient

kye = KyeClient(base_url="https://gw.example/v1")

decision = kye.authorize({
    "actor":               {"entity_id": "kye:ent:acme:ai_agent:01J..."},
    "acting_on_behalf_of": {"delegation_id": "kye:del:acme:01J..."},
    "action":              "payment.transfer",
    # Action Admissibility inputs — declare the effect + classify risk
    "action_declaration":  {"effect_class": "financial", "reversibility": "irreversible"},
    "action_risk_classification": {"risk_tier": "high", "required_oversight_mode": "two_person"},
})

assert decision["decision"] == "allow_with_constraints", decision["reasons"]
```

```
// go get github.com/kye-protocol/sdk-go
package main

import (
    "context"
    "github.com/kye-protocol/sdk-go/pkg/kye"
)

func main() {
    c := kye.NewClient("https://gw.example")
    d, err := c.Authorize(context.Background(), kye.AuthorizeRequest{
        Action: "document.render",
        Actor:  kye.Actor{EntityID: "kye:ent:acme:ai_agent:01J..."},
    })
    if err != nil { panic(err) }
    // d.Decision == "allow_with_constraints"
    _ = d
}
```

```
# Plain HTTP — no SDK required
curl -X POST https://gw.example/v1/runtime/authorize \
  -H 'content-type: application/json' \
  -H 'idempotency-key: 8c4a-...' \
  -d '{
    "actor":               { "entity_id": "kye:ent:acme:ai_agent:01J..." },
    "acting_on_behalf_of": { "delegation_id": "kye:del:acme:01J..." },
    "action":              "payment.transfer",
    "action_declaration":  { "effect_class": "financial", "reversibility": "irreversible" },
    "action_risk_classification": { "risk_tier": "high", "required_oversight_mode": "two_person" }
  }'

# → { "decision":"allow_with_constraints", "reasons":["delegation_active","scope_match"], ... }
```

## Subscribe to signed signals in 10 minutes.

KYE Protocol™ is event-driven. The KYE™ Signal Bus™ emits signed, replayable events for every authority, decision, recovery and evidence-pack lifecycle. Build a verifier:

1. Install the SDK — `npm i @kye/sdk` · `pip install kye-sdk` · `go get github.com/kye-protocol/sdk-go`
2. Stand up a `POST` receiver that accepts the canonical JSON envelope (schema: `https://kyeprotocol.com/schemas/signal.json`).
3. On receive: `verifyWebhook(envelope, headers)` against the publisher's published JWKS. Multiple signing-suite bindings are supported per the conformance pack.
4. Deduplicate by `event_id` using the SDK's idempotency helper or your store. Replays carry the same id.
5. Switch on `event_type` — `kye.authority.revoked`, `kye.decision.requires_approval`, `kye.capability.quarantined`, `kye.evidence_pack.generated`, etc. (see [24 event families](https://kyeprotocol.com/protocol/#signals)).
6. Ack with `2xx` within the publisher's timeout. Anything else → retry with exponential backoff → eventual DLQ.
7. Subscribe via `POST /v1/webhook-endpoints` with your URL + filter expression + retry policy. Test via `:test`.

**Open contract:** envelope schema, every event-family schema, verifier SDK, reference Gateway webhook handler + retry loop + DLQ + replay endpoint, conformance test vectors.

[Full signals reference →](https://kyeprotocol.com/protocol/#signals) [Verifier SDKs](https://github.com/KYE-Protocol)

## More for developers

- [KYE™ Developers — Conformance](https://kyeprotocol.com/developers/conformance/)
- [Operating Model · KYE™ Developer Tools™](https://kyeprotocol.com/developers/docs/operating-model/)
- [governed.sh — install governed agents & apps, or build with the SDK](https://kyeprotocol.com/developers/governed/)
- [KYE™ Developers — Quickstart](https://kyeprotocol.com/developers/quickstart/)
- [KYE™ Developers — Schemas](https://kyeprotocol.com/developers/schemas/)
- [KYE™ Developers — SDKs](https://kyeprotocol.com/developers/sdks/)
- [Build with KYE™](https://kyeprotocol.com/build/)
- [Agent-native (one file)](https://kyeprotocol.com/agent-native/)
- [Documentation hub](https://kyeprotocol.com/docs/)

## Get an API key and make one call.

[Get an API key](https://app.kyeprotocol.com/api-keys.html) [API reference](https://kyeprotocol.com/developers/api/)
