Start here
Get a signed decision before an agent acts.
Start with an assessment. Use Action Authority when an executor must enforce one exact consequential action, and Control Coverage when you need to show what boundary is live.
1 · Create a test key
In the Console, create an API key with assess:write. A test key begins with fky_test_; a live key begins with fky_live_. The raw secret is displayed once, so store it in a server-side secret manager, never in a browser or repository.
export FIDACY_ENGINE_API_KEY='fky_test_…'
2 · Assess a payment mandate
Send the intended payment before your application asks a rail to move money. The response is a signed assessment. It is a decision record, not by itself an execution gate.
curl -s https://api.fidacy.com/v1/assess \
-H "Authorization: Bearer $FIDACY_ENGINE_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"mandate": {
"vct": "mandate.payment.1",
"transaction_id": "a1b2c3d4e5f6a7b8c9d0e1f2a3b4c5d6",
"payee": { "id": "merchant_demo", "name": "Demo Store" },
"payment_amount": { "amount": 4299, "currency": "EUR" },
"payment_instrument": { "id": "pi_demo", "type": "card" }
}
}'{
"decision": "approve",
"assessmentId": "…",
"riskPayloadJws": "eyJ…",
"signingKeyId": "…",
"outcome": { "…": "…" }
}- ·
approvemeans the assessment returned an allow outcome under its input and policy. - ·
reviewmeans hold or step up to a control you own. - ·
denymeans do not continue the action.
3 · Verify the signed result
The riskPayloadJwsis a compact Ed25519 JWS. A recipient can verify its signature using Fidacy's public key set, without an API key.
See Verify a signed payload for copyable Node and Python verification examples.
When the action itself must be stopped
An assessment advises the caller. For an execution boundary, create a bounded action mandate, request a decision for the exact action and redeem the one-time grant in the executor immediately before the side effect. A missing, expired or replayed grant must stop that executor.