Integrations · what KYE composes with

KYE doesn’t replace your stack — it binds authority across it.

KYE composes with the identity, policy, agent runtime, payment rail, KYC / KYB / KYA, SIEM, GRC, and audit stack you already run. Each row carries a conformance status: shipping, reference pattern, or roadmap.

Identity & access

OAuth 2.0 · OIDC · SAML · SPIFFE · mTLS · passkeys.

IntegrationConnector typeStatusNotes
OAuth 2.0 + PKCEoauth_oidcShippingToken introspection feeds the actor + on-behalf-of binding.
OpenID Connectoauth_oidcShippingID-token claims map into the principal entity.
SAML 2.0samlReference patternFederated identity assertion translated into KYE delegations.
SCIM 2.0scimReference patternWorkforce provisioning into the entity registry.
SPIFFE / SPIREspiffe_spireShippingSPIFFE ID becomes the workload entity URN; SVID feeds attestation.
mTLSmtlsShippingFront-the-Gateway pattern: reverse proxy verifies; passes X-Client-Cert-Subject.
Passkeys / WebAuthnpasskeyReference patternPasskey assertion as the “principal authenticated” factor in step-up flows.
Verifiable Credentials (W3C)credential_issuerShippingNative: kye-credentials-v1 profile.
Policy engines

OPA · Cerbos · AWS Cedar.

IntegrationConnector typeStatusNotes
Open Policy Agent (OPA / Rego)opaShippingReference policy bundles: Core (kye_authz.rego) + Payments (payments_spdp.rego).
CerboscerbosShippingDerived-roles + resource-policy bundles for the Core profile + sector overlays.
AWS Cedaraws_cedarReference patternCedar policy bundle for the Core profile.
AuthZEN (OpenID)authzenReference patternKYE Decision API maps onto the AuthZEN authorization-API shape.
Agent runtime

MCP · agent frameworks · tool gateways.

IntegrationConnector typeStatusNotes
Model Context Protocol (MCP)mcp_serverRoadmap (v1.1)KYE MCP Server design specification published; reference implementation ships v1.1.
Agent runtime (LangChain / LlamaIndex / DSPy / custom)agent_runtimeReference patternSDK-level integration: the agent loop calls POST /v1/runtime/authorize before any external action.
Tool gateway (function-calling)tool_gatewayReference patternEach tool invocation becomes a capability invocation with a Decision Map.
Payment rails

IPG / MPG / card-token / wallet / open-banking initiation.

IntegrationConnector typeStatusNotes
Internet payment gateway (IPG)internet_payment_gatewayReference patternPre-authorisation hook; KYE authorises the agent before the gateway processes the payment.
Mobile payment gateway (MPG)mobile_payment_gatewayReference patternSame shape as IPG; mobile-flow attestation.
Card token / vaultcard_tokenShippingSchema rejects raw PAN; token-only references; PCI null CDE.
WalletwalletShippingWallet-bound spend control; per-instrument scope intersection.
Open-banking payment initiationopen_bankingReference patternPSD2 / PSD3 SCA binding; consent-to-authority mapping.
OpenBankProject (OBP)open_bankingRoadmapSandbox connector pattern documented; managed connector planned.
KYC / KYB / KYA

Verification providers feed the entity record; KYE binds authority.

Identity-verification vendors are upstream of the KYE entity record. KYE does not duplicate KYC; it consumes the verification result + the verifier’s evidence URI and binds the result into the entity’s authority surface.

Integration shapeConnector typeStatusNotes
KYC provider (per-individual identity)kyc_providerReference patternPersona / Sumsub / Onfido / Trulioo — result becomes a signed credential bound to the person entity.
KYB provider (business identity)kyb_providerReference patternMiddesk / Mesh / Companies House feed bound to the business entity record.
KYA provider (agent identity / passport)kya_providerReference patternAgent passport schema; Skyfire / Coinbase x402-style agent identity feeds.
Agent passportagent_passportShippingNative: kye-attestation-v1 profile.
SIEM & SOAR

Signed events stream into your security stack.

IntegrationConnector typeStatusNotes
Splunk HTTP Event CollectorsplunkShippingReference exporter under plugins.
Microsoft SentinelsentinelShippingSentinel exporter plugin.
DatadogdatadogReference patternLogs API + custom-metric integration.
AWS CloudWatchcloudwatchReference patternLog group + EventBridge fan-out.
Kafka / EventBridge / SNSkafkaReference patternEvent bus fan-out for signed signals.
GRC

Control mappings feed your governance system of record.

Integration shapeConnector typeStatusNotes
GRC platform (AuditBoard / Vanta / Drata / OneTrust)grcReference patternKYE evidence packs feed the platform’s evidence repository; control-mapping JSON exports.
Control-mapping exportcontrol_mappingShipping266 control mappings across 13 horizontal frameworks (SOC 2, ISO 27001, PCI DSS, PSD2/3, DORA, NIS2, EU AI Act, ISO 42001, NIST AI RMF, NIST 800-207, NIST CSF, GDPR, FedRAMP) plus sector overlays.
Self-audit attestationself_auditShippingNative: kye-self-audit-attestation-v1 profile.
Audit / OSCAL / SCITT

Standards the auditor already accepts.

StandardStatusNotes
OSCAL (NIST SP 800-53A) — component definition / SSP / assessment results / POA&MShippingReference exporter under plugins; see oscal.html.
SCITT receipts (Supply-Chain Integrity, Transparency & Trust)Reference patternTransparency receipt envelope aligns with SCITT; native via kye-transparency-v1.
RFC 8949 COSE_Sign1ShippingWebhook signing profile; binary CBOR receipts.

Ready to see your AI agents flagged?

Start in shadow mode. We’ll deliver your first Evidence Pack in 4–8 weeks.