Integrations · what KYE™ composes with

KYE™ doesn’t replace your stack — it binds authority across it.

KYE™ composes with the identity, policy, agent runtime, payment rail, KYC / KYB / KYA, SIEM, GRC, and audit stack you already run. Each row carries a conformance status: shipping, reference pattern, or roadmap.

Identity & access

OAuth 2.0 · OIDC · SAML · SPIFFE · mTLS · passkeys.

Every claim here is backed by the open KYE Protocol™ contracts and verifiable end-to-end from the publisher's JWKS — you check it yourself, you don't take our word for it.

IntegrationConnector typeStatusNotes
OAuth 2.0 + PKCEoauth_oidcShippingToken introspection feeds the actor + on-behalf-of binding.
OpenID Connectoauth_oidcShippingID-token claims map into the principal entity.
SAML 2.0samlReference patternFederated identity assertion translated into KYE™ delegations.
SCIM 2.0scimReference patternWorkforce provisioning into the entity registry.
SPIFFE / SPIREspiffe_spireShippingSPIFFE ID becomes the workload entity URN; SVID feeds attestation.
mTLSmtlsShippingFront-the-Gateway pattern: reverse proxy verifies; passes X-Client-Cert-Subject.
Passkeys / WebAuthnpasskeyReference patternPasskey assertion as the “principal authenticated” factor in step-up flows.
Verifiable Credentials (W3C)credential_issuerShippingNative: credentials dictionary + compliance-evidence rule pack.
Policy engines

OPA · Cerbos · AWS Cedar.

Every claim here is backed by the open KYE Protocol™ contracts and verifiable end-to-end from the publisher's JWKS — you check it yourself, you don't take our word for it.

IntegrationConnector typeStatusNotes
Open Policy Agent (OPA / Rego)opaShippingReference policy bundles: Core (kye_authz.rego) + Payments (payments_spdp.rego).
CerboscerbosShippingDerived-roles + resource-policy bundles for the Core profile + sector overlays.
AWS Cedaraws_cedarReference patternCedar policy bundle for the Core profile.
AuthZEN (OpenID)authzenReference patternKYE™ Decision API maps onto the AuthZEN authorization-API shape.
Agent runtime

MCP · agent frameworks · tool gateways.

Every claim here is backed by the open KYE Protocol™ contracts and verifiable end-to-end from the publisher's JWKS — you check it yourself, you don't take our word for it.

IntegrationConnector typeStatusNotes
Model Context Protocol (MCP)mcp_serverRoadmap (v1.1)KYE™ MCP Server design specification published; reference implementation ships v1.1.
Agent runtime (LangChain / LlamaIndex / DSPy / custom)agent_runtimeReference patternSDK-level integration: the agent loop calls POST /v1/runtime/authorize before any external action.
Tool gateway (function-calling)tool_gatewayReference patternEach tool invocation becomes a capability invocation with a Decision Map™.
Payment rails

IPG / MPG / card-token / wallet / open-banking initiation.

Every claim here is backed by the open KYE Protocol™ contracts and verifiable end-to-end from the publisher's JWKS — you check it yourself, you don't take our word for it.

IntegrationConnector typeStatusNotes
Internet payment gateway (IPG)internet_payment_gatewayReference patternPre-authorisation hook; KYE™ authorises the agent before the gateway processes the payment.
Mobile payment gateway (MPG)mobile_payment_gatewayReference patternSame shape as IPG; mobile-flow attestation.
Card token / vaultcard_tokenShippingSchema rejects raw PAN; token-only references; PCI null CDE.
WalletwalletShippingWallet-bound spend control; per-instrument scope intersection.
Open-banking payment initiationopen_bankingReference patternPSD2 / PSD3 SCA binding; consent-to-authority mapping.
OpenBankProject (OBP)open_bankingRoadmapSandbox connector pattern documented; managed connector planned.
KYC / KYB / KYA

Verification providers feed the entity record; KYE™ binds authority.

Identity-verification vendors are upstream of the KYE™ entity record. KYE™ does not duplicate KYC; it consumes the verification result + the verifier’s evidence URI and binds the result into the entity’s authority surface.

Integration shapeConnector typeStatusNotes
KYC provider (per-individual identity)kyc_providerReference patternPersona / Sumsub / Onfido / Trulioo — result becomes a signed credential bound to the person entity.
KYB provider (business identity)kyb_providerReference patternMiddesk / Mesh / Companies House feed bound to the business entity record.
KYA provider (agent identity / passport)kya_providerReference patternAgent passport schema; Skyfire / Coinbase x402-style agent identity feeds.
Agent passportagent_passportShippingNative: mcp-agent-runtime profile + action-admissibility rule pack.
SIEM & SOAR

Signed events stream into your security stack.

Every claim here is backed by the open KYE Protocol™ contracts and verifiable end-to-end from the publisher's JWKS — you check it yourself, you don't take our word for it.

IntegrationConnector typeStatusNotes
Splunk HTTP Event CollectorsplunkShippingReference exporter under plugins.
Microsoft SentinelsentinelShippingSentinel exporter plugin.
DatadogdatadogReference patternLogs API + custom-metric integration.
AWS CloudWatchcloudwatchReference patternLog group + EventBridge fan-out.
Kafka / EventBridge / SNSkafkaReference patternEvent bus fan-out for signed signals.
GRC

Control mappings feed your governance system of record.

Every claim here is backed by the open KYE Protocol™ contracts and verifiable end-to-end from the publisher's JWKS — you check it yourself, you don't take our word for it.

Integration shapeConnector typeStatusNotes
GRC platform (AuditBoard / Vanta / Drata / OneTrust)grcReference patternKYE™ evidence packs feed the platform’s evidence repository; control-mapping JSON exports.
Control-mapping exportcontrol_mappingShipping289 control mappings across 13 horizontal frameworks (SOC 2, ISO 27001, PCI DSS, PSD2/3, DORA, NIS2, EU AI Act, ISO 42001, NIST AI RMF, NIST 800-207, NIST CSF, GDPR, FedRAMP) plus sector overlays.
Self-audit attestationself_auditShippingNative: evidence-replay profile + compliance-evidence rule pack.
Audit / OSCAL / SCITT

Standards the auditor already accepts.

Every claim here is backed by the open KYE Protocol™ contracts and verifiable end-to-end from the publisher's JWKS — you check it yourself, you don't take our word for it.

StandardStatusNotes
OSCAL (NIST SP 800-53A) — component definition / SSP / assessment results / POA&MShippingReference exporter under plugins; see oscal.html.
SCITT receipts (Supply-Chain Integrity, Transparency & Trust)Reference patternTransparency receipt envelope aligns with SCITT; native via the evidence-replay profile + compliance-evidence rule pack.
RFC 8949 COSE_Sign1ShippingWebhook signing profile; binary CBOR receipts.
Integration Catalog

Every named ecosystem partner — and exactly how KYE™ relates to each.

One honest catalog of 85 ecosystem targets, derived from the canonical integration registry. 48 authority adapters · 19 governed agents · 10 ecosystem partners · 8 policy engines. KYE™ governs the action — keep your model, your framework and your agent. Already on a GRC platform? See the dedicated GRC Integrations™ hub.

Authority adapter KYE governs the action / consumes the signal as policy input / exports evidence. Governed agent §0.30 — KYE governs the agents, never builds them. Ecosystem partner infrastructure / silicon — listed, not an authority surface.

neurology Model & inference (20)

Keep your model and your inference provider — KYE governs the data and purpose binding at the moment of inference, and seals an Evidence Pack™ before the call commits.

  • Baseten Authority adapterDeclared (per-tenant wiring)
  • Cohere Authority adapterDeclared (per-tenant wiring)
  • DeepSeek Authority adapterDeclared (per-tenant wiring)
  • Fireworks.ai Authority adapterDeclared (per-tenant wiring)
  • Gcore Authority adapterDeclared (per-tenant wiring)
  • Groq Authority adapterDeclared (per-tenant wiring)
  • Jina Authority adapterDeclared (per-tenant wiring)
  • Lambda.ai Authority adapterDeclared (per-tenant wiring)
  • Mistral Authority adapterDeclared (per-tenant wiring)
  • Modal Authority adapterDeclared (per-tenant wiring)
  • Nebius Authority adapterDeclared (per-tenant wiring)
  • Nvidia NIM Authority adapterDeclared (per-tenant wiring)
  • Ollama Authority adapterDeclared (per-tenant wiring)
  • OpenAI Authority adapterDeclared (per-tenant wiring)
  • OpenRouter Authority adapterDeclared (per-tenant wiring)
  • Perplexity Authority adapterDeclared (per-tenant wiring)
  • Qwen Authority adapterDeclared (per-tenant wiring)
  • SambaNova Authority adapterDeclared (per-tenant wiring)
  • Together.ai Authority adapterDeclared (per-tenant wiring)
  • vLLM Authority adapterDeclared (per-tenant wiring)

account_tree Agent frameworks (4)

Keep your agent framework — §0.30/§32: KYE governs the agents it produces as first-class principals; it never runs or replaces the framework.

  • CrewAI Governed agentDeclared (per-tenant wiring)
  • Haystack Governed agentDeclared (per-tenant wiring)
  • LangChain Governed agentDeclared (per-tenant wiring)
  • LlamaIndex Governed agentDeclared (per-tenant wiring)

smart_toy Autonomous agents & AI apps (12)

Keep your AI product — §0.30: KYE governs each consequential action its agents take at the commit boundary; it does not build the product.

  • Agent.ai Governed agentDeclared (per-tenant wiring)
  • Dust.tt Governed agentDeclared (per-tenant wiring)
  • ElevenLabs Governed agentDeclared (per-tenant wiring)
  • Fin.ai Governed agentDeclared (per-tenant wiring)
  • Genspark Governed agentDeclared (per-tenant wiring)
  • Jasper.ai Governed agentDeclared (per-tenant wiring)
  • Lovable Governed agentDeclared (per-tenant wiring)
  • Make.com Governed agentDeclared (per-tenant wiring)
  • Manus Governed agentDeclared (per-tenant wiring)
  • Plain.com Governed agentDeclared (per-tenant wiring)
  • StackAI Governed agentDeclared (per-tenant wiring)
  • Viktor Governed agentDeclared (per-tenant wiring)

code Coding agents (3)

Keep your coding agent — §52: KYE binds it as a principal and governs its consequential tool-calls with a §0.3 evidence chain.

  • AugmentCode Governed agentDeclared (per-tenant wiring)
  • Cline Governed agentDeclared (per-tenant wiring)
  • Cursor Governed agentDeclared (per-tenant wiring)

database Vector & retrieval (4)

Keep your vector store — KYE governs retrieval as a data-use action and cites sources through the §71 Document Intelligence contract; it never reimplements the engine.

  • Firecrawl Authority adapterDeclared (per-tenant wiring)
  • Milvus Authority adapterDeclared (per-tenant wiring)
  • Qdrant Authority adapterDeclared (per-tenant wiring)
  • Weaviate Authority adapterDeclared (per-tenant wiring)

monitoring ML observability & eval (2)

Keep your observability stack — KYE consumes its sensed signals as admissibility inputs and evidence; KYE is not an observability platform.

  • Arize Authority adapterDeclared (per-tenant wiring)
  • Weights & Biases Authority adapterDeclared (per-tenant wiring)

model_training MLOps & model lifecycle (4)

Keep your MLOps platform — KYE consumes model-registry and deployment-stage signals as policy input (is this model approved for this purpose?).

  • Amazon SageMaker Authority adapterDeclared (per-tenant wiring)
  • Kubeflow Authority adapterDeclared (per-tenant wiring)
  • MLflow Authority adapterDeclared (per-tenant wiring)
  • Vertex AI Authority adapterDeclared (per-tenant wiring)

schema DataOps & pipelines (4)

Keep your pipelines — KYE governs data movement as a §31 data-use action, purpose-scoped and evidence-sealed at the asset boundary.

  • Apache Airflow Authority adapterDeclared (per-tenant wiring)
  • Dagster Authority adapterDeclared (per-tenant wiring)
  • dbt Authority adapterDeclared (per-tenant wiring)
  • Fivetran Authority adapterDeclared (per-tenant wiring)

auto_fix_high AIOps & automated remediation (3)

Keep your AIOps platform — KYE gates the authority of an automated remediation before it commits, and seals the decision.

  • Datadog Authority adapterDeclared (per-tenant wiring)
  • Dynatrace Authority adapterDeclared (per-tenant wiring)
  • PagerDuty Authority adapterDeclared (per-tenant wiring)

security SOC, SIEM & EDR (4)

Keep your SOC stack — KYE gates the authority of an automated response action and exports its own signed evidence into the SIEM.

  • CrowdStrike Authority adapterDeclared (per-tenant wiring)
  • Microsoft Sentinel Authority adapterDeclared (per-tenant wiring)
  • Panther Authority adapterDeclared (per-tenant wiring)
  • Splunk Authority adapterDeclared (per-tenant wiring)

key Identity & authenticators (6)

Keep your IdP — KYE treats IAM as necessary-but-insufficient: authentication establishes who; KYE establishes whether this principal may act, and seals the evidence.

  • Auth0 Authority adapterDeclared (per-tenant wiring)
  • Duo Authority adapterDeclared (per-tenant wiring)
  • Google Authenticator Authority adapterDeclared (per-tenant wiring)
  • Microsoft Entra Authority adapterDeclared (per-tenant wiring)
  • Okta Authority adapterDeclared (per-tenant wiring)
  • WorkOS Authority adapterDeclared (per-tenant wiring)

shield Enforcement points (1)

Keep your enforcement point — KYE turns it into a PEP that calls the KYE PDP inline and enforces the returned authority decision at the wire.

  • F5 Authority adapterDeclared (per-tenant wiring)

cloud Cloud & data infrastructure (6)

Ecosystem partners — KYE governance is infrastructure-agnostic (§51/§0.10): KYE runs on this substrate but never requires it.

  • Cloudflare Ecosystem partnerDeclared (per-tenant wiring)
  • Databricks Ecosystem partnerDeclared (per-tenant wiring)
  • DigitalOcean Ecosystem partnerDeclared (per-tenant wiring)
  • OVHcloud Ecosystem partnerDeclared (per-tenant wiring)
  • Red Hat Ecosystem partnerDeclared (per-tenant wiring)
  • SUSE Ecosystem partnerDeclared (per-tenant wiring)

memory Hardware & silicon substrate (4)

Ecosystem listing only — N/A: substrate, not an authority surface. KYE governs decisions, not hardware; there is no adapter for silicon and never a faked one (§0.29).

  • Arm Ecosystem partnerN/A: substrate
  • Intel Ecosystem partnerN/A: substrate
  • Micron Ecosystem partnerN/A: substrate
  • Seagate Ecosystem partnerN/A: substrate

policy Policy engines (8)

Surfaced from the canonical policy-engine adapters dictionary — KYE delegates the raw allow/deny to your engine and retains Purpose Permission™, Authority Resolution, Authority Finality, Evidence Pack™ and Replay-Proof™ above it.

  • AGENTCOREPolicy engine
  • AWS-VERIFIED-PERMISSIONSPolicy engine
  • CEDARPolicy engine
  • CERBOSPolicy engine
  • CUSTOMPolicy engine
  • MICROSOFT-AGTPolicy engine
  • NATIVEPolicy engine
  • OPAPolicy engine

Ready to see your AI agents flagged?

Start in shadow mode. We’ll deliver your first Evidence Pack™ in 4–8 weeks.