KYE™ doesn’t replace your stack — it binds authority across it.
KYE™ composes with the identity, policy, agent runtime, payment rail, KYC / KYB / KYA, SIEM, GRC, and audit stack you already run. Each row carries a conformance status: shipping, reference pattern, or roadmap.
OAuth 2.0 · OIDC · SAML · SPIFFE · mTLS · passkeys.
Every claim here is backed by the open KYE Protocol™ contracts and verifiable end-to-end from the publisher's JWKS — you check it yourself, you don't take our word for it.
| Integration | Connector type | Status | Notes |
|---|---|---|---|
| OAuth 2.0 + PKCE | oauth_oidc | Shipping | Token introspection feeds the actor + on-behalf-of binding. |
| OpenID Connect | oauth_oidc | Shipping | ID-token claims map into the principal entity. |
| SAML 2.0 | saml | Reference pattern | Federated identity assertion translated into KYE™ delegations. |
| SCIM 2.0 | scim | Reference pattern | Workforce provisioning into the entity registry. |
| SPIFFE / SPIRE | spiffe_spire | Shipping | SPIFFE ID becomes the workload entity URN; SVID feeds attestation. |
| mTLS | mtls | Shipping | Front-the-Gateway pattern: reverse proxy verifies; passes X-Client-Cert-Subject. |
| Passkeys / WebAuthn | passkey | Reference pattern | Passkey assertion as the “principal authenticated” factor in step-up flows. |
| Verifiable Credentials (W3C) | credential_issuer | Shipping | Native: credentials dictionary + compliance-evidence rule pack. |
OPA · Cerbos · AWS Cedar.
Every claim here is backed by the open KYE Protocol™ contracts and verifiable end-to-end from the publisher's JWKS — you check it yourself, you don't take our word for it.
| Integration | Connector type | Status | Notes |
|---|---|---|---|
| Open Policy Agent (OPA / Rego) | opa | Shipping | Reference policy bundles: Core (kye_authz.rego) + Payments (payments_spdp.rego). |
| Cerbos | cerbos | Shipping | Derived-roles + resource-policy bundles for the Core profile + sector overlays. |
| AWS Cedar | aws_cedar | Reference pattern | Cedar policy bundle for the Core profile. |
| AuthZEN (OpenID) | authzen | Reference pattern | KYE™ Decision API maps onto the AuthZEN authorization-API shape. |
MCP · agent frameworks · tool gateways.
Every claim here is backed by the open KYE Protocol™ contracts and verifiable end-to-end from the publisher's JWKS — you check it yourself, you don't take our word for it.
| Integration | Connector type | Status | Notes |
|---|---|---|---|
| Model Context Protocol (MCP) | mcp_server | Roadmap (v1.1) | KYE™ MCP Server design specification published; reference implementation ships v1.1. |
| Agent runtime (LangChain / LlamaIndex / DSPy / custom) | agent_runtime | Reference pattern | SDK-level integration: the agent loop calls POST /v1/runtime/authorize before any external action. |
| Tool gateway (function-calling) | tool_gateway | Reference pattern | Each tool invocation becomes a capability invocation with a Decision Map™. |
IPG / MPG / card-token / wallet / open-banking initiation.
Every claim here is backed by the open KYE Protocol™ contracts and verifiable end-to-end from the publisher's JWKS — you check it yourself, you don't take our word for it.
| Integration | Connector type | Status | Notes |
|---|---|---|---|
| Internet payment gateway (IPG) | internet_payment_gateway | Reference pattern | Pre-authorisation hook; KYE™ authorises the agent before the gateway processes the payment. |
| Mobile payment gateway (MPG) | mobile_payment_gateway | Reference pattern | Same shape as IPG; mobile-flow attestation. |
| Card token / vault | card_token | Shipping | Schema rejects raw PAN; token-only references; PCI null CDE. |
| Wallet | wallet | Shipping | Wallet-bound spend control; per-instrument scope intersection. |
| Open-banking payment initiation | open_banking | Reference pattern | PSD2 / PSD3 SCA binding; consent-to-authority mapping. |
| OpenBankProject (OBP) | open_banking | Roadmap | Sandbox connector pattern documented; managed connector planned. |
Verification providers feed the entity record; KYE™ binds authority.
Identity-verification vendors are upstream of the KYE™ entity record. KYE™ does not duplicate KYC; it consumes the verification result + the verifier’s evidence URI and binds the result into the entity’s authority surface.
| Integration shape | Connector type | Status | Notes |
|---|---|---|---|
| KYC provider (per-individual identity) | kyc_provider | Reference pattern | Persona / Sumsub / Onfido / Trulioo — result becomes a signed credential bound to the person entity. |
| KYB provider (business identity) | kyb_provider | Reference pattern | Middesk / Mesh / Companies House feed bound to the business entity record. |
| KYA provider (agent identity / passport) | kya_provider | Reference pattern | Agent passport schema; Skyfire / Coinbase x402-style agent identity feeds. |
| Agent passport | agent_passport | Shipping | Native: mcp-agent-runtime profile + action-admissibility rule pack. |
Signed events stream into your security stack.
Every claim here is backed by the open KYE Protocol™ contracts and verifiable end-to-end from the publisher's JWKS — you check it yourself, you don't take our word for it.
| Integration | Connector type | Status | Notes |
|---|---|---|---|
| Splunk HTTP Event Collector | splunk | Shipping | Reference exporter under plugins. |
| Microsoft Sentinel | sentinel | Shipping | Sentinel exporter plugin. |
| Datadog | datadog | Reference pattern | Logs API + custom-metric integration. |
| AWS CloudWatch | cloudwatch | Reference pattern | Log group + EventBridge fan-out. |
| Kafka / EventBridge / SNS | kafka | Reference pattern | Event bus fan-out for signed signals. |
Control mappings feed your governance system of record.
Every claim here is backed by the open KYE Protocol™ contracts and verifiable end-to-end from the publisher's JWKS — you check it yourself, you don't take our word for it.
| Integration shape | Connector type | Status | Notes |
|---|---|---|---|
| GRC platform (AuditBoard / Vanta / Drata / OneTrust) | grc | Reference pattern | KYE™ evidence packs feed the platform’s evidence repository; control-mapping JSON exports. |
| Control-mapping export | control_mapping | Shipping | 289 control mappings across 13 horizontal frameworks (SOC 2, ISO 27001, PCI DSS, PSD2/3, DORA, NIS2, EU AI Act, ISO 42001, NIST AI RMF, NIST 800-207, NIST CSF, GDPR, FedRAMP) plus sector overlays. |
| Self-audit attestation | self_audit | Shipping | Native: evidence-replay profile + compliance-evidence rule pack. |
Standards the auditor already accepts.
Every claim here is backed by the open KYE Protocol™ contracts and verifiable end-to-end from the publisher's JWKS — you check it yourself, you don't take our word for it.
| Standard | Status | Notes |
|---|---|---|
| OSCAL (NIST SP 800-53A) — component definition / SSP / assessment results / POA&M | Shipping | Reference exporter under plugins; see oscal.html. |
| SCITT receipts (Supply-Chain Integrity, Transparency & Trust) | Reference pattern | Transparency receipt envelope aligns with SCITT; native via the evidence-replay profile + compliance-evidence rule pack. |
| RFC 8949 COSE_Sign1 | Shipping | Webhook signing profile; binary CBOR receipts. |
Every named ecosystem partner — and exactly how KYE™ relates to each.
One honest catalog of 85 ecosystem targets, derived from the canonical integration registry. 48 authority adapters · 19 governed agents · 10 ecosystem partners · 8 policy engines. KYE™ governs the action — keep your model, your framework and your agent. Already on a GRC platform? See the dedicated GRC Integrations™ hub.
neurology Model & inference (20)
Keep your model and your inference provider — KYE™ governs the data and purpose binding at the moment of inference, and seals an Evidence Pack™ before the call commits.
- Baseten Authority adapterDeclared (per-tenant wiring)
- Cohere Authority adapterDeclared (per-tenant wiring)
- DeepSeek Authority adapterDeclared (per-tenant wiring)
- Fireworks.ai Authority adapterDeclared (per-tenant wiring)
- Gcore Authority adapterDeclared (per-tenant wiring)
- Groq Authority adapterDeclared (per-tenant wiring)
- Jina Authority adapterDeclared (per-tenant wiring)
- Lambda.ai Authority adapterDeclared (per-tenant wiring)
- Mistral Authority adapterDeclared (per-tenant wiring)
- Modal Authority adapterDeclared (per-tenant wiring)
- Nebius Authority adapterDeclared (per-tenant wiring)
- Nvidia NIM Authority adapterDeclared (per-tenant wiring)
- Ollama Authority adapterDeclared (per-tenant wiring)
- OpenAI Authority adapterDeclared (per-tenant wiring)
- OpenRouter Authority adapterDeclared (per-tenant wiring)
- Perplexity Authority adapterDeclared (per-tenant wiring)
- Qwen Authority adapterDeclared (per-tenant wiring)
- SambaNova Authority adapterDeclared (per-tenant wiring)
- Together.ai Authority adapterDeclared (per-tenant wiring)
- vLLM Authority adapterDeclared (per-tenant wiring)
account_tree Agent frameworks (4)
Keep your agent framework — §0.30/§32: KYE™ governs the agents it produces as first-class principals; it never runs or replaces the framework.
- CrewAI Governed agentDeclared (per-tenant wiring)
- Haystack Governed agentDeclared (per-tenant wiring)
- LangChain Governed agentDeclared (per-tenant wiring)
- LlamaIndex Governed agentDeclared (per-tenant wiring)
smart_toy Autonomous agents & AI apps (12)
Keep your AI product — §0.30: KYE™ governs each consequential action its agents take at the commit boundary; it does not build the product.
- Agent.ai Governed agentDeclared (per-tenant wiring)
- Dust.tt Governed agentDeclared (per-tenant wiring)
- ElevenLabs Governed agentDeclared (per-tenant wiring)
- Fin.ai Governed agentDeclared (per-tenant wiring)
- Genspark Governed agentDeclared (per-tenant wiring)
- Jasper.ai Governed agentDeclared (per-tenant wiring)
- Lovable Governed agentDeclared (per-tenant wiring)
- Make.com Governed agentDeclared (per-tenant wiring)
- Manus Governed agentDeclared (per-tenant wiring)
- Plain.com Governed agentDeclared (per-tenant wiring)
- StackAI Governed agentDeclared (per-tenant wiring)
- Viktor Governed agentDeclared (per-tenant wiring)
code Coding agents (3)
Keep your coding agent — §52: KYE™ binds it as a principal and governs its consequential tool-calls with a §0.3 evidence chain.
- AugmentCode Governed agentDeclared (per-tenant wiring)
- Cline Governed agentDeclared (per-tenant wiring)
- Cursor Governed agentDeclared (per-tenant wiring)
database Vector & retrieval (4)
Keep your vector store — KYE™ governs retrieval as a data-use action and cites sources through the §71 Document Intelligence contract; it never reimplements the engine.
- Firecrawl Authority adapterDeclared (per-tenant wiring)
- Milvus Authority adapterDeclared (per-tenant wiring)
- Qdrant Authority adapterDeclared (per-tenant wiring)
- Weaviate Authority adapterDeclared (per-tenant wiring)
monitoring ML observability & eval (2)
Keep your observability stack — KYE™ consumes its sensed signals as admissibility inputs and evidence; KYE™ is not an observability platform.
- Arize Authority adapterDeclared (per-tenant wiring)
- Weights & Biases Authority adapterDeclared (per-tenant wiring)
model_training MLOps & model lifecycle (4)
Keep your MLOps platform — KYE™ consumes model-registry and deployment-stage signals as policy input (is this model approved for this purpose?).
- Amazon SageMaker Authority adapterDeclared (per-tenant wiring)
- Kubeflow Authority adapterDeclared (per-tenant wiring)
- MLflow Authority adapterDeclared (per-tenant wiring)
- Vertex AI Authority adapterDeclared (per-tenant wiring)
schema DataOps & pipelines (4)
Keep your pipelines — KYE™ governs data movement as a §31 data-use action, purpose-scoped and evidence-sealed at the asset boundary.
- Apache Airflow Authority adapterDeclared (per-tenant wiring)
- Dagster Authority adapterDeclared (per-tenant wiring)
- dbt Authority adapterDeclared (per-tenant wiring)
- Fivetran Authority adapterDeclared (per-tenant wiring)
auto_fix_high AIOps & automated remediation (3)
Keep your AIOps platform — KYE™ gates the authority of an automated remediation before it commits, and seals the decision.
- Datadog Authority adapterDeclared (per-tenant wiring)
- Dynatrace Authority adapterDeclared (per-tenant wiring)
- PagerDuty Authority adapterDeclared (per-tenant wiring)
security SOC, SIEM & EDR (4)
Keep your SOC stack — KYE™ gates the authority of an automated response action and exports its own signed evidence into the SIEM.
- CrowdStrike Authority adapterDeclared (per-tenant wiring)
- Microsoft Sentinel Authority adapterDeclared (per-tenant wiring)
- Panther Authority adapterDeclared (per-tenant wiring)
- Splunk Authority adapterDeclared (per-tenant wiring)
key Identity & authenticators (6)
Keep your IdP — KYE™ treats IAM as necessary-but-insufficient: authentication establishes who; KYE™ establishes whether this principal may act, and seals the evidence.
- Auth0 Authority adapterDeclared (per-tenant wiring)
- Duo Authority adapterDeclared (per-tenant wiring)
- Google Authenticator Authority adapterDeclared (per-tenant wiring)
- Microsoft Entra Authority adapterDeclared (per-tenant wiring)
- Okta Authority adapterDeclared (per-tenant wiring)
- WorkOS Authority adapterDeclared (per-tenant wiring)
shield Enforcement points (1)
Keep your enforcement point — KYE™ turns it into a PEP that calls the KYE™ PDP inline and enforces the returned authority decision at the wire.
- F5 Authority adapterDeclared (per-tenant wiring)
cloud Cloud & data infrastructure (6)
Ecosystem partners — KYE™ governance is infrastructure-agnostic (§51/§0.10): KYE™ runs on this substrate but never requires it.
- Cloudflare Ecosystem partnerDeclared (per-tenant wiring)
- Databricks Ecosystem partnerDeclared (per-tenant wiring)
- DigitalOcean Ecosystem partnerDeclared (per-tenant wiring)
- OVHcloud Ecosystem partnerDeclared (per-tenant wiring)
- Red Hat Ecosystem partnerDeclared (per-tenant wiring)
- SUSE Ecosystem partnerDeclared (per-tenant wiring)
memory Hardware & silicon substrate (4)
Ecosystem listing only — N/A: substrate, not an authority surface. KYE™ governs decisions, not hardware; there is no adapter for silicon and never a faked one (§0.29).
- Arm Ecosystem partnerN/A: substrate
- Intel Ecosystem partnerN/A: substrate
- Micron Ecosystem partnerN/A: substrate
- Seagate Ecosystem partnerN/A: substrate
policy Policy engines (8)
Surfaced from the canonical policy-engine adapters dictionary — KYE™ delegates the raw allow/deny to your engine and retains Purpose Permission™, Authority Resolution™, Authority Finality™, Evidence Pack™ and Replay-Proof™ above it.
- AGENTCOREPolicy engine
- AWS-VERIFIED-PERMISSIONSPolicy engine
- CEDARPolicy engine
- CERBOSPolicy engine
- CUSTOMPolicy engine
- MICROSOFT-AGTPolicy engine
- NATIVEPolicy engine
- OPAPolicy engine
Ready to see your AI agents flagged?
Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.