Integrations
Connect the agent to the boundary you control.
Fidacy is agent-agnostic because the trust boundary is the executor, not the model. Any agent can request an action. Money, CRM, email, files or infrastructure only move when the connector verifies and redeems the exact signed grant.
Choose the right integration
| Need | Integration | What it proves |
|---|---|---|
| Connect an application-owned or custom runtime | @fidacy/sdk | The existing SDK uses the account key to request signed assessments, create bounded authority and retrieve evidence. |
| Give an MCP host Fidacy tools | @fidacy/mcp | The host can request a signed assessment or use local firewall tools. |
| Assess an application tool call | @fidacy/langchain or @fidacy/openai-agents | The wrapper evaluated that connected tool before its call continued. |
| Block one named side effect | Action Authority | A Fidacy executor redeemed an exact one-time grant before its own side-effect path continued. |
| Show the operating boundary | Control Coverage | Current heartbeats, historic hard gates and evidence gaps are reported separately. |
MCP hosts
@fidacy/mcpruns over stdio, so a compatible host such as Claude Code, Cursor, Codex, Gemini CLI or another MCP client can expose Fidacy as a tool server. Add it to the host configuration and keep the engine key in that host's secret environment. OpenClaw uses Fidacy's native plugin when local in-process enforcement is required.
{
"mcpServers": {
"fidacy": {
"command": "npx",
"args": ["-y", "@fidacy/mcp"],
"env": {
"FIDACY_ENGINE_URL": "https://api.fidacy.com",
"FIDACY_ENGINE_API_KEY": "fky_test_…"
}
}
}
}The server exposes assessment, payment-firewall and evidence tools. The exact set available depends on its configured engine and firewall-core connection. A tool result is not retroactive protection: call it before the connected action, and have the host or executor honor a deny.
Core MCP operations
- ·
assess_actionsends a consequential proposal to the engine and returns a signedapprove,reviewordenyresult. - ·
request_paymentevaluates a payment against the configured local firewall mandate. It does not settle a payment itself. - ·
verify_mandateandget_audit_proofexpose the configured firewall's authority and evidence paths. - ·
anchor_artifactandcheck_artifactwork from a local file path or SHA-256, so the original file is not uploaded as part of anchoring.
Application tool wrappers
The LangChain and OpenAI Agents packages wrap an application-owned tool invocation. They are useful when you own the code that performs the action and can make the wrapper part of that path. Keep an explicit failure policy: an unavailable decision must never become an approval.
import { guardTools } from "@fidacy/langchain";
const guarded = guardTools([refundTool], {
apiKey: process.env.FIDACY_ENGINE_API_KEY,
});
// Invoke guarded[0], not the original refundTool, on the execution path.Any application-owned agent runtime
@fidacy/sdk is the canonical API integration. Use the same API key created in the Fidacy dashboard. The SDK already exposes signed assessments, Action Authority mandates, one-time grant decisions, decision feeds and Incident Packs, so a custom runtime does not need a second Fidacy client.
import { Fidacy, hashActionContext } from "@fidacy/sdk";
const fidacy = new Fidacy({
apiKey: process.env.FIDACY_ENGINE_API_KEY!,
});
const contextHash = await hashActionContext(localRequest);
const decision = await fidacy.actionMandates.decide(mandateId, {
action: "stripe.refund.create",
resource: "stripe:payment_intent:pi_123",
contextHash,
});
if (!decision.grant) throw new Error("Action refused");
// Give the grant only to the connector that owns the downstream credential.For money or another irreversible effect
Use a bounded Action Authority mandate. Fidacy decides the exact action, resource and local context hash. Only an ALLOWcontains a short-lived grant. Redeem that grant atomically inside the executor immediately before it calls the protected system.
A redeemed grant proves the Fidacy executor accepted the grant before continuing its own path. Store the downstream PSP, CRM or other system receipt separately if you need to prove the external effect completed.
Keep the scope visible
Use Control Coverage alongside an integration when an operator needs to know whether the connector is live, whether its latest session is complete, and where the evidence ends. Historic grant redemption and a current heartbeat are intentionally different states.