Quesen is the deterministic decision-and-receipt core for agent actions — a typed security context in, a
PASS / REVIEW / BLOCK / SKIPverdict out, with machine reason codes and a receipt you can re-run byte-for-byte and prove. No model inference is in the scoring path, so the same input always yields the same verdict. It is built to sit behind injection detection, on top of agent identity, and to bill per decision (ASP/402).Unlike log-based governance layers whose audit trail is their word, kept by them, a Quesen receipt is independently verifiable by the caller — recomputable, and (engine signing enabled) Ed25519-signed. See
docs/architecture-gap-closers.mdand client-side enforcement + receipt verification inquesen-sdk≥ 0.5.0.This repository is the public developer portal. It contains only documentation, integration guides, examples, registry manifests, and reference links. No engine source code lives here. Quesen's engine implementation is sovereign, non-public infrastructure.
Live production
| Surface | URL |
|---|---|
| REST API | https://web-production-aa5ba.up.railway.app |
| MCP (Streamable HTTP) | https://web-production-aa5ba.up.railway.app/mcp |
| OpenAPI 3.1 | https://web-production-aa5ba.up.railway.app/openapi.json |
| Swagger UI | https://web-production-aa5ba.up.railway.app/docs |
| Health | https://web-production-aa5ba.up.railway.app/health |
| Version | https://web-production-aa5ba.up.railway.app/version |
Fastest path — no install, no signup, no card. Self-serve a free sandbox key and run a
real deterministic decision against production. Full guide: docs/QUICKSTART.md
· try it in the browser at senueren.co.za/try.
# 1 · get a free sandbox key
curl -X POST https://web-production-aa5ba.up.railway.app/sandbox/keys
# 2 · evaluate an action (use the api_key from step 1)
curl -X POST https://web-production-aa5ba.up.railway.app/validate \
-H "X-API-Key: sk_sandbox_..." \
-H "Content-Type: application/json" \
-d '{"domain_age_days": 1, "engagement_ratio": 0.95, "scam_keyword_count": 4}'
# -> {"decision":"SKIP","risk_score":1.0,"conflict_triggers":[...],"input_snapshot_hash":"..."}Published. The SDKs are live on PyPI and npm (
quesen-sdk0.5.0/ npm0.5.0;quesen-langchain,quesen-crewai,quesen-autogen0.3.0). Thebase_url+X-API-Key(including the sandbox key above) are identical across all SDKs.
pip install quesen-sdk # PyPI: https://pypi.org/project/quesen-sdk/from quesen_sdk import QuesenClient
q = QuesenClient(base_url="https://web-production-aa5ba.up.railway.app",
api_key="YOUR_KEY") # a sandbox key from /sandbox/keys works here
verdict = q.validate(domain_age_days=1, engagement_ratio=0.95, scam_keyword_count=4)
if verdict.decision == "SKIP":
return # respect the deterministic answernpm i quesen-sdk # npm: https://www.npmjs.com/package/quesen-sdkimport { QuesenClient } from "quesen-sdk";
const q = new QuesenClient({
baseUrl: "https://web-production-aa5ba.up.railway.app",
apiKey: process.env.QUESEN_API_KEY,
});
const verdict = await q.validate({
domain_age_days: 1,
engagement_ratio: 0.95,
scam_keyword_count: 4,
});| Framework | Package | Repository |
|---|---|---|
| LangChain / LangGraph | quesen-langchain |
Shxnque/quesen-langchain |
| CrewAI | quesen-crewai |
Shxnque/quesen-crewai |
| AutoGen v0.4+ | quesen-autogen |
Shxnque/quesen-autogen |
| Python (core) | quesen-sdk |
Shxnque/quesen-sdk-py |
| JavaScript / TypeScript | quesen-sdk (npm) |
Shxnque/quesen-sdk-js |
Quesen exposes five MCP tools over the production endpoint. See
docs/mcp.md for the client-config snippet.
Autonomous agents make more decisions per second than any human oversight can audit. When those decisions involve capital — launching a token, opening a position, executing a trade, greenlighting a smart-contract deployment — the marginal cost of a bad decision is fatal.
Quesen answers exactly one question:
Should the calling agent proceed with this action?
Inputs are typed. Outputs are one of PROCEED, REVIEW, SKIP, always with a
risk_score in [0.0, 1.0], a confidence in [0.0, 1.0], and the exact
conflict rules that fired. Same inputs → same output. Every time. Every
response embeds engine_version, weights, and thresholds. Fully
reproducible. Fully auditable.
- Not an LLM wrapper. No prompts. No probabilities.
- Not a chatbot. It is A2A infrastructure.
- Not a KYC/identity system. It scores risk, not identity.
- Not chain-locked / framework-locked / LLM-locked. Ecosystem-neutral by design.
- Quickstart — first decision in under 10 minutes (free sandbox key).
- Architecture overview
- Integration guide
- API reference
- MCP setup
- Pricing tiers
- FAQ
- Registry status
Published receipts are independently reproducible from this repo alone — no hosted service or private engine required:
python3 verify/verify_receipts.py # offline, stdlib-only
python3 verify/verify_receipts.py --live # also cross-check the live engineAll six UCP #724 vectors show a byte-for-byte three-way match between the
published fixture, the public reference, and the live engine
(verify/README.md, verify/three_way_match.json).
That doc also states honestly where independent verification stops today (the
production ruleset commit_sha is not publicly resolvable; receipts are not yet
cryptographically issuer-signed).
The egress/authority decision subset — the part security integrators gate on — is now independently verdict-replayable offline too, with zero network:
python3 evaluation/conformance/verify_conformance.py # offline; recomputes decision+reasons+hashSix cases (OWASP-agentic + LoopX prepared-Effect PASS/REVIEW/BLOCK) recompute
byte-for-byte from the public reference evaluator, plus a prod-1→prod-2
integrity-flip check — no signup, key, or hosted call
(evaluation/conformance/README.md).
- Moltbook post-guard — deterministic pre-post safety gate for autonomous social agents.
- OpenClaw MCP plugin — wiring Quesen as an MCP-native guardrail into OpenClaw-style agents.
- Production:
https://web-production-aa5ba.up.railway.app - Health check:
GET /healthreturns{"status":"ok","engine_version":"1.10.0"} - Version snapshot:
GET /versionreturns full engine + billing + on-chain flags (ASP/1.0) - Uptime and version widget on senueren.co.za/quesen
Quesen is discoverable via Model Context Protocol registries and the standard
agent-directory ecosystem. See docs/registries.md for
the current state of each submission. Manifests:
smithery.yaml— Smithery.ai (canonical)mcp.json— MCP.so / generic MCP client (canonical).well-known/ai-plugin.json— OpenAI plugin manifest /.well-known/ai-plugin.jsonautodiscoveryllms.txt— machine-readable summary for LLM crawlers
This is a documentation-only repository. Engine PRs cannot be accepted here.
If you have integration-specific feedback, please open an issue or read CONTRIBUTING.md.
SDK contributions belong in the corresponding public SDK repository:
- Python: Shxnque/quesen-sdk-py
- JavaScript: Shxnque/quesen-sdk-js
- LangChain: Shxnque/quesen-langchain
- CrewAI: Shxnque/quesen-crewai
- AutoGen: Shxnque/quesen-autogen
Security issues: please read SECURITY.md before filing publicly.
MIT. See LICENSE.