Integrations

Connect the agent to the boundary you control.

Fidacy is agent-agnostic because the trust boundary is the executor, not the model. Any agent can request an action. Money, CRM, email, files or infrastructure only move when the connector verifies and redeems the exact signed grant.

Choose the right integration

NeedIntegrationWhat it proves
Connect an application-owned or custom runtime@fidacy/sdkThe existing SDK uses the account key to request signed assessments, create bounded authority and retrieve evidence.
Give an MCP host Fidacy tools@fidacy/mcpThe host can request a signed assessment or use local firewall tools.
Assess an application tool call@fidacy/langchain or @fidacy/openai-agentsThe wrapper evaluated that connected tool before its call continued.
Block one named side effectAction AuthorityA Fidacy executor redeemed an exact one-time grant before its own side-effect path continued.
Show the operating boundaryControl CoverageCurrent heartbeats, historic hard gates and evidence gaps are reported separately.
Installing an MCP server is not a universal hard gate.An agent can only be governed at action paths that call Fidacy, and a real-world effect is only stopped at an executor that refuses to run without the required grant.

MCP hosts

@fidacy/mcpruns over stdio, so a compatible host such as Claude Code, Cursor, Codex, Gemini CLI or another MCP client can expose Fidacy as a tool server. Add it to the host configuration and keep the engine key in that host's secret environment. OpenClaw uses Fidacy's native plugin when local in-process enforcement is required.

{
  "mcpServers": {
    "fidacy": {
      "command": "npx",
      "args": ["-y", "@fidacy/mcp"],
      "env": {
        "FIDACY_ENGINE_URL": "https://api.fidacy.com",
        "FIDACY_ENGINE_API_KEY": "fky_test_…"
      }
    }
  }
}

The server exposes assessment, payment-firewall and evidence tools. The exact set available depends on its configured engine and firewall-core connection. A tool result is not retroactive protection: call it before the connected action, and have the host or executor honor a deny.

Core MCP operations

  • ·assess_action sends a consequential proposal to the engine and returns a signed approve, review or deny result.
  • ·request_payment evaluates a payment against the configured local firewall mandate. It does not settle a payment itself.
  • ·verify_mandate and get_audit_proof expose the configured firewall's authority and evidence paths.
  • ·anchor_artifact and check_artifact work from a local file path or SHA-256, so the original file is not uploaded as part of anchoring.

Application tool wrappers

The LangChain and OpenAI Agents packages wrap an application-owned tool invocation. They are useful when you own the code that performs the action and can make the wrapper part of that path. Keep an explicit failure policy: an unavailable decision must never become an approval.

import { guardTools } from "@fidacy/langchain";

const guarded = guardTools([refundTool], {
  apiKey: process.env.FIDACY_ENGINE_API_KEY,
});

// Invoke guarded[0], not the original refundTool, on the execution path.

Any application-owned agent runtime

@fidacy/sdk is the canonical API integration. Use the same API key created in the Fidacy dashboard. The SDK already exposes signed assessments, Action Authority mandates, one-time grant decisions, decision feeds and Incident Packs, so a custom runtime does not need a second Fidacy client.

import { Fidacy, hashActionContext } from "@fidacy/sdk";

const fidacy = new Fidacy({
  apiKey: process.env.FIDACY_ENGINE_API_KEY!,
});

const contextHash = await hashActionContext(localRequest);
const decision = await fidacy.actionMandates.decide(mandateId, {
  action: "stripe.refund.create",
  resource: "stripe:payment_intent:pi_123",
  contextHash,
});

if (!decision.grant) throw new Error("Action refused");
// Give the grant only to the connector that owns the downstream credential.

For money or another irreversible effect

Use a bounded Action Authority mandate. Fidacy decides the exact action, resource and local context hash. Only an ALLOWcontains a short-lived grant. Redeem that grant atomically inside the executor immediately before it calls the protected system.

A redeemed grant proves the Fidacy executor accepted the grant before continuing its own path. Store the downstream PSP, CRM or other system receipt separately if you need to prove the external effect completed.

If the agent still has the raw credential or another route to the same system, that route is outside coverage. Remove parallel credentials and expose only the gated connector to make the boundary enforceable.

Keep the scope visible

Use Control Coverage alongside an integration when an operator needs to know whether the connector is live, whether its latest session is complete, and where the evidence ends. Historic grant redemption and a current heartbeat are intentionally different states.

Signed payloads can be verified with Fidacy's public JWKS without an account. Verification establishes the issuer's signature over the retained payload. It does not create visibility into actions outside the connected control boundary.