the developer journey

How KIFF actually connects.

The commercial page shows what a card does. This page shows what is underneath it: the operational domain a card narrows against, the Guard seam that reaches your agent's tool call, and the three lines your code needs.

make reality executable

Turn business truth into a system agents can act through.

Model the lifecycle once: what is true now, what actions are possible, and who has authority. Every agent you add next reads the same rule.

1 Establish reality Events produce shared state that every actor can read and replay.
2 Define agency Typed actions declare what is possible, which parameters matter, and who has authority.
3 Record consequences KIFF validates before your application executes, then records the result for everyone who follows.
same pattern · different work
order CARTPAIDFULFILLEDRETURNED
invoice ISSUEDAPPROVEDPAIDRECONCILED
claim OPENEDREVIEWEDAPPROVEDSETTLED
case OPENEDASSIGNEDRESOLVEDCLOSED
peopleagentsservicespartnerssystems
guard connects the stack

Different frameworks. Same reality.

Keep Agno, LangGraph, OpenAI, Google ADK, Strands, n8n, or your own stack. KIFF Guard connects their pre-execution seam to the same operational domain, so state, rules, and history survive every model and framework change.

01, install the guard
your shell
pip install kiff-guard   # or: npm i @kiff/kiff-guard
02, put it in front of the action

Pick your stack. The KIFF side is identical everywhere, the same three-field contract; only the adapter and one attach line change.

agent.py
from kiff_guard import Guard, HTTPClient, ToolMap
from kiff_guard.adapters.agno import agno_hook

tm = ToolMap().bind("refund_order", action="REFUND_ORDER",
                    entity_type="Order", entity_arg="order_id")
guard = Guard(client=HTTPClient(api_key=KEY, tool_map=tm),
              tenant="acme", agent="refunds", mode="enforce")
guard.connect(adapter="agno")

agent = Agent(model=..., tools=[refund_order],
              tool_hooks=[agno_hook(guard)])   # decides before the tool runs
agent.py
from kiff_guard import Guard, HTTPClient, ToolMap
from kiff_guard.adapters.langgraph import kiff_wrap_tool_call

tm = ToolMap().bind("refund_order", action="REFUND_ORDER",
                    entity_type="Order", entity_arg="order_id")
guard = Guard(client=HTTPClient(api_key=KEY, tool_map=tm),
              tenant="acme", agent="refunds", mode="enforce")
guard.connect(adapter="langgraph")

agent = create_agent(model=..., tools=[refund_order],
                     middleware=[kiff_wrap_tool_call(guard)])
agent.py
from kiff_guard import Guard, HTTPClient, ToolMap
from kiff_guard.adapters.openai_agents import kiff_tool_input_guardrail

tm = ToolMap().bind("refund_order", action="REFUND_ORDER",
                    entity_type="Order", entity_arg="order_id")
guard = Guard(client=HTTPClient(api_key=KEY, tool_map=tm),
              tenant="acme", agent="refunds", mode="enforce")
guard.connect(adapter="openai-agents")

@function_tool(tool_input_guardrails=[kiff_tool_input_guardrail(guard)])
def refund_order(order_id: str, amount: int, reason: str): ...
agent.py
from kiff_guard import Guard, HTTPClient, ToolMap
from kiff_guard.adapters.google_adk import kiff_before_tool_callback

tm = ToolMap().bind("refund_order", action="REFUND_ORDER",
                    entity_type="Order", entity_arg="order_id")
guard = Guard(client=HTTPClient(api_key=KEY, tool_map=tm),
              tenant="acme", agent="refunds", mode="enforce")
guard.connect(adapter="google-adk")

agent = Agent(tools=[refund_order],
              before_tool_callback=kiff_before_tool_callback(guard))
agent.py
from kiff_guard import Guard, HTTPClient, ToolMap
from kiff_guard.adapters.pydantic_ai import kiff_before_tool_execute

tm = ToolMap().bind("refund_order", action="REFUND_ORDER",
                    entity_type="Order", entity_arg="order_id")
guard = Guard(client=HTTPClient(api_key=KEY, tool_map=tm),
              tenant="acme", agent="refunds", mode="enforce")
guard.connect(adapter="pydantic-ai")

agent = Agent(model=...,
              before_tool_execute=kiff_before_tool_execute(guard))
agent.py
from kiff_guard import Guard, HTTPClient, ToolMap
from kiff_guard.adapters.strands import kiff_hook_provider

tm = ToolMap().bind("refund_order", action="REFUND_ORDER",
                    entity_type="Order", entity_arg="order_id")
guard = Guard(client=HTTPClient(api_key=KEY, tool_map=tm),
              tenant="acme", agent="refunds", mode="enforce")
guard.connect(adapter="strands")

agent = Agent(model=..., tools=[refund_order],
              hooks=[kiff_hook_provider(guard)])
agent.py
from kiff_guard import Guard, HTTPClient, ToolMap
from kiff_guard.adapters.microsoft_agent_framework import kiff_guard_middleware

tm = ToolMap().bind("refund_order", action="REFUND_ORDER",
                    entity_type="Order", entity_arg="order_id")
guard = Guard(client=HTTPClient(api_key=KEY, tool_map=tm),
              tenant="acme", agent="refunds", mode="enforce")
guard.connect(adapter="ms-agent-framework")

agent = Agent(tools=[refund_order],
              middleware=[kiff_guard_middleware(guard)])
agent.py
from kiff_guard import Guard, HTTPClient, ToolMap
from kiff_guard.adapters.hermes import register_kiff_guard

tm = ToolMap().bind("refund_order", action="REFUND_ORDER",
                    entity_type="Order", entity_arg="order_id")
guard = Guard(client=HTTPClient(api_key=KEY, tool_map=tm),
              tenant="acme", agent="refunds", mode="enforce")
guard.connect(adapter="hermes")

register_kiff_guard(ctx, guard)   # in your Hermes plugin's register()
agent.ts
import { Guard, HTTPClient, ToolMap } from "@kiff/kiff-guard";
import { registerKiffGuard } from "@kiff/kiff-guard/adapters/openclaw";

const tm = new ToolMap().bind("refund_order", {
  action: "REFUND_ORDER", entityType: "Order", entityArg: "order_id" });
const client = new HTTPClient({ apiKey: KEY, toolMap: tm });
const guard = new Guard({ client, tenant: "acme", agent: "refunds", mode: "enforce" });

registerKiffGuard(ctx, guard);   // in your OpenClaw plugin
agent.py
# No adapter needed. Wrap the one function that moves money.
def issue_refund(order, amount):
    d = kiff.decide("REFUND_ORDER", entity=order, amount=amount)
    if not d.allowed:
        return d                         # blocked or held, never execute
    payments.refund(order, amount)       # your code, unchanged
shell
# No SDK. Any language. POST the proposed action; act only on "allowed".
curl -s https://api.kiff.dev/v1/proposals/decide \
  -H "Authorization: Bearer $KIFF_KEY" -H "Content-Type: application/json" \
  -d '{"id":"rd-4471","entity_id":"order-4471","entity_type":"Order",
       "action_name":"REFUND_ORDER","actor_id":"refunds",
       "parameters":{"amount":8400,"reason":"damaged"}}'
# -> {"outcome":"allowed"}   then POST .../execute for a signed receipt

// same three-field contract on every stack: entity + action + parameters -> one verdict.

make it yours

Let your coding agent define the operational reality.

The guard connects your runtime. The domain is the contract it decides against, install the KIFF domain skill and your coding agent writes and extends your kiff.yaml against the real grammar: states, approvals, permissions, executors.

install the skill in your agent
Cursor
curl -fsSL https://kiff.dev/skills/kiff-domains.md \
  -o .cursor/rules/kiff-domains.mdc
Instructions for your agent
Set up the KIFF domain skill in this project: run `curl -fsSL https://kiff.dev/skills/kiff-domains.md -o .cursor/rules/kiff-domains.mdc` to add the skill, read it, then help me author a kiff.yaml domain for my riskiest action (states, actions, approvals, permissions, executors) and connect it to KIFF Cloud, validate with POST /v1/me/domain/validate, then PUT /v1/me/domain.
Kiro
mkdir -p .kiro/skills/kiff-domains && curl -fsSL https://kiff.dev/skills/kiff-domains.md \
  -o .kiro/skills/kiff-domains/SKILL.md
Instructions for your agent
Set up the KIFF domain skill in this project: run `mkdir -p .kiro/skills/kiff-domains && curl -fsSL https://kiff.dev/skills/kiff-domains.md -o .kiro/skills/kiff-domains/SKILL.md` to add the skill, read it, then help me author a kiff.yaml domain for my riskiest action (states, actions, approvals, permissions, executors) and connect it to KIFF Cloud, validate with POST /v1/me/domain/validate, then PUT /v1/me/domain.
Codex
curl -fsSL https://kiff.dev/skills/kiff-domains.md >> AGENTS.md
Instructions for your agent
Set up the KIFF domain skill in this project: run `curl -fsSL https://kiff.dev/skills/kiff-domains.md >> AGENTS.md` to add the skill, read it, then help me author a kiff.yaml domain for my riskiest action (states, actions, approvals, permissions, executors) and connect it to KIFF Cloud, validate with POST /v1/me/domain/validate, then PUT /v1/me/domain.
Claude Code
mkdir -p ~/.claude/skills/kiff-domains && curl -fsSL https://kiff.dev/skills/kiff-domains.md \
  -o ~/.claude/skills/kiff-domains/SKILL.md
Instructions for your agent
Set up the KIFF domain skill in this project: run `mkdir -p ~/.claude/skills/kiff-domains && curl -fsSL https://kiff.dev/skills/kiff-domains.md -o ~/.claude/skills/kiff-domains/SKILL.md` to add the skill, read it, then help me author a kiff.yaml domain for my riskiest action (states, actions, approvals, permissions, executors) and connect it to KIFF Cloud, validate with POST /v1/me/domain/validate, then PUT /v1/me/domain.
Copilot
mkdir -p ~/.copilot/skills/kiff-domains && curl -fsSL https://kiff.dev/skills/kiff-domains.md \
  -o ~/.copilot/skills/kiff-domains/SKILL.md
Instructions for your agent
Set up the KIFF domain skill in this project: run `mkdir -p ~/.copilot/skills/kiff-domains && curl -fsSL https://kiff.dev/skills/kiff-domains.md -o ~/.copilot/skills/kiff-domains/SKILL.md` to add the skill, read it, then help me author a kiff.yaml domain for my riskiest action (states, actions, approvals, permissions, executors) and connect it to KIFF Cloud, validate with POST /v1/me/domain/validate, then PUT /v1/me/domain.
Gemini CLI
curl -fsSL https://kiff.dev/skills/kiff-domains.md >> GEMINI.md
Instructions for your agent
Set up the KIFF domain skill in this project: run `curl -fsSL https://kiff.dev/skills/kiff-domains.md >> GEMINI.md` to add the skill, read it, then help me author a kiff.yaml domain for my riskiest action (states, actions, approvals, permissions, executors) and connect it to KIFF Cloud, validate with POST /v1/me/domain/validate, then PUT /v1/me/domain.
Aider
curl -fsSL https://kiff.dev/skills/kiff-domains.md >> AGENTS.md
Instructions for your agent
Set up the KIFF domain skill in this project: run `curl -fsSL https://kiff.dev/skills/kiff-domains.md >> AGENTS.md` to add the skill, read it, then help me author a kiff.yaml domain for my riskiest action (states, actions, approvals, permissions, executors) and connect it to KIFF Cloud, validate with POST /v1/me/domain/validate, then PUT /v1/me/domain.
Amp
curl -fsSL https://kiff.dev/skills/kiff-domains.md >> AGENTS.md
Instructions for your agent
Set up the KIFF domain skill in this project: run `curl -fsSL https://kiff.dev/skills/kiff-domains.md >> AGENTS.md` to add the skill, read it, then help me author a kiff.yaml domain for my riskiest action (states, actions, approvals, permissions, executors) and connect it to KIFF Cloud, validate with POST /v1/me/domain/validate, then PUT /v1/me/domain.
OpenCode
curl -fsSL https://kiff.dev/skills/kiff-domains.md >> AGENTS.md
Instructions for your agent
Set up the KIFF domain skill in this project: run `curl -fsSL https://kiff.dev/skills/kiff-domains.md >> AGENTS.md` to add the skill, read it, then help me author a kiff.yaml domain for my riskiest action (states, actions, approvals, permissions, executors) and connect it to KIFF Cloud, validate with POST /v1/me/domain/validate, then PUT /v1/me/domain.
Windsurf
mkdir -p .windsurf/rules && curl -fsSL https://kiff.dev/skills/kiff-domains.md \
  -o .windsurf/rules/kiff-domains.md
Instructions for your agent
Set up the KIFF domain skill in this project: run `mkdir -p .windsurf/rules && curl -fsSL https://kiff.dev/skills/kiff-domains.md -o .windsurf/rules/kiff-domains.md` to add the skill, read it, then help me author a kiff.yaml domain for my riskiest action (states, actions, approvals, permissions, executors) and connect it to KIFF Cloud, validate with POST /v1/me/domain/validate, then PUT /v1/me/domain.

// then ask your agent: "add an ISSUE_CREDIT action to the refund domain, PAID-only"

see it in action

Three lines. Your code still runs the action.

One call, before the side effect. KIFF answers; your function returns early or proceeds untouched.

your_app.py
def issue_refund(order, amount):
+ d = kiff.decide("issue_refund", order=order, amount=amount)
+ if not d.allowed:
+ return d # blocked or held, you never execute
payments.refund(order, amount) # your code, unchanged
issue_refund · order 4471 · €42 allowed
Right state, right permission, under the threshold. Runs, and nobody reads it.
issue_refund · order 2287 · €88 refused
Same call, same code path. Refused on the day's authority, and your function never reaches the payment line.
the agent asks for a higher ceiling refused
Its own credential cannot raise its own limit. A limit the agent can raise is not a limit: that is the whole separation.
Run it live, against a real agent →