Packages
The public @kindgi/* packages (Apache-2.0). They share one version. Most
apps need only @kindgi/sdk, with @kindgi/cli for development; the others
are its building blocks, and the pieces you swap or extend.
@kindgi/adapter-model-anthropic: Anthropic ModelProvider for @kindgi/capabilities. Wraps @anthropic-ai/sdk with the framework's provider-neutral interface: message-trail ↔ Messages API translation, prompt-caching-aware cost accounting, and lazy API-key resolution so per-tenant registries can close over a SecretStore scope. Non-streaming, tool-use enabled. Wire per-tenant in the provider registry (see @kindgi/capabilities).@kindgi/adapter-model-gemini: Gemini ModelProvider for @kindgi/capabilities, on Vertex AI. Wraps @google/genai with the framework's provider-neutral interface: message-trail ↔ generateContent translation, function calling with thought signatures, token and cost accounting including thinking tokens, and Google Application Default Credentials (or a service-account key from the secret store). Non-streaming, tool-use enabled.@kindgi/adapter-model-in-process: In-process ModelProvider for @kindgi/capabilities. Runs small instruction-tuned LLMs inside the Node.js process via @huggingface/transformers (ONNX runtime; no external processes, no API keys). SmolLM2-360M by default (~273MB q4f16, Apache 2.0, tuned for function calling); SmolLM2-135M and Qwen3-0.6B selectable via themodelsoption. prepareInProcessModel downloads a model ahead of first use and streams progress. Positioned as the cheapest tier for routing/classification/smoke-test workloads — not a replacement for hosted providers on real reasoning tasks.@kindgi/adapter-model-openai-compat: OpenAI-compatible ModelProvider for @kindgi/capabilities. Points at any endpoint speaking the OpenAI Chat Completions wire format — OpenAI proper, Ollama (/v1), vLLM, llama-server, LM Studio, OpenRouter, Groq, Together, Fireworks, DeepInfra, LiteLLM proxy (base URLs exported as BASE_URLS), or any other compatible endpoint. One adapter, many backends. Cost per 1K tokens is supplied by the caller (from the provider's public pricing) since the API surface itself doesn't expose it.@kindgi/agents: Agent primitive for Kindgi. Composes capabilities (model routing), tools (execution), memory (facts + retrieval), guardrails (declarative guardrails), and provenance into a single declarative unit. Agents are data-as-code — a defineAgent() call produces a durable definition that runs on the kernel, with first-class multi-turn conversations, streaming output, and a provenance record per turn.@kindgi/api: REST + SSE HTTP surface for Kindgi™. createApp assembles a Hono app serving the /v1/* REST API (bearer or session-token auth; OpenAPI 3.1 document at /v1/openapi.json) and an optional S3-compatible /s3/* surface (SigV4), over caller-plugged bindings for the runtime (runs, agents, flows, HITL, supervisor) and for storage. Route conventions: docs/API-ROUTE-CONVENTIONS.md.@kindgi/audit-events: Kindgi™ audit events contract. Types only: AuditEvent (the audit record — id, tenantId, projectId, kind, timestamp, actor, outcome, run / agent / flow / correlation ids, versioned payload), AuditEventFilter and AuditEventPage, AuditEventBinding (the caller-plugged append / query / purge interface) with its input and result shapes, and the AuditEventError union. No runtime code. A reference in-memory binding is @kindgi/audit-events-inmemory; durable bindings are provided by the Kindgi runtime.@kindgi/audit-events-inmemory: Reference in-memoryAuditEventBindingadapter for dev + tests. Implements the full@kindgi/audit-eventscontract (idempotent append, cursor-paginated query, per-kind purge) and pins down the cursor shape and ordering durable adapters match, so consumers swap adapters without code changes.@kindgi/authz: Kindgi™ authorization shape. The public vocabulary and interfaces of Kindgi's authorization stack: Action verbs (read/write/execute/…), ObjectType enum (agent/flow/tool/…), ResourceRef, Principal (who is calling, with delegation and downscoping), the AuthzCheckBinding decision-point interface and its Decision (allow/deny + reason), FGA tuple builders and the TupleEnqueueHook outbox contract, the 403 DenyPayload shape, and reviewer roles. Types and pure functions — no runtime state. The FGA store, the check implementation and the tuple worker are supplied by the deployment.@kindgi/blob-binding: Kindgi™ blob storage binding contract. Types only: the BlobStorageBinding interface that storage implementations provide and @kindgi/api consumes — blobId-addressed put / get / head / list / delete, S3-compatible putByKey / getByKey / headByKey / deleteByKey / listByPrefix, and multipart initiate / upload-part / complete / abort / list-parts — its input and result shapes (BlobPutInput, MultipartInitiateInput, BlobFilter, BlobMeta, BlobRead, BlobListPage, BlobDeleteOutcome, S3ListPage, MultipartListPartsPage), and the BlobError union. No runtime code.@kindgi/capabilities: Capability declarations + provider router for Kindgi™. Agents declare what they need from a model (features such as structured-output or tool-use, context window, cost, region, latency, provider and model allow/deny lists) and what they prefer; the router picks a registered (provider, model) pair that satisfies every hard constraint plus tenant policy, ranked by soft preferences, and reports per requirement which candidates it rejected when none qualify. Also the provider-neutral ModelProvider contract, a tenant-scoped provider registry, and an adapter-factory registry. Capability kinds are open strings matched by equality; llm-inference is the default.@kindgi/cli: Command-line interface for Kindgi™ — the sovereign AI OS. Create a pack, run it on your machine (kindgi dev), build, sign and deploy it, and work with a running Kindgi API from the terminal.@kindgi/compliance: Kindgi™ compliance evidence contract. Types for the Evidence wire record and its sub-types (EvidenceActor, EvidenceSubject, EvidenceKind, EvidenceOutcome, EvidencePayload, EvidenceSignature, ProvenanceRef, ActorKind; ComplianceEvidence alias), the ComplianceProvider seam (EmitEvidenceInput, ListEvidenceFilter, EvidenceSigner), the ComplianceEvidenceGenerator interface with its inputs (RecordFromRunOptions, RunEvidenceContext, ModelCallSummary, ToolInvocationSummary, GuardrailResultSummary), EvidenceFilter, EvidencePage, SignedEvidenceBundle and EvidenceBundleBody, the classifier file format (ComplianceClassifierFile, Classification, LoadedClassifier), and the ComplianceError union. Runtime exports: the EVIDENCE_KINDS list, the pure auditEventToEvidence transform, and emitResolveEvent / emitLifecycleEvent, which append env-* and secret-* audit events to an AuditEventBinding. The generator implementation and the classifier loader are provided by the Kindgi runtime or by the caller.@kindgi/crypto: Kindgi™ cryptographic primitives. Ed25519 signatures for asymmetric use (signed audit bundles, provenance exports, deployment attestations) and HMAC-SHA256 for symmetric use (webhook payloads). Includes SigningKeyBinding interface + in-memory reference impl, PEM/base64 key format converters, and typed error interfaces. Pure Node built-ins, zero runtime deps. Deployments plug their own key store (KMS, Vault, env-var) via SigningKeyBinding.@kindgi/dev-echo-provider: Deterministic dev-only ModelProvider — no LLM key, no network, no cost. Emits a two-message scripted response (tool-call → text) so an agent turn completes in milliseconds. For dev, tests and tutorials. NEVER for production — every real deployment plugs in a real model provider adapter (Anthropic, OpenAI-compat, etc.) instead.@kindgi/dotenv-file: Dotenv files the way applications read them (dotenv grammar, verified against the version Next.js bundles), expanded (${VAR}), layered (.env < .env.local) and edited losslessly. Used by @kindgi/secrets-dotenv. Zero runtime dependencies.@kindgi/embedding: Kindgi™ embedding provider contract and registry: the EmbeddingProvider interface (embed / dimensions / describe), the EmbeddingProviderRegistry interface with the createEmbeddingProviderRegistry in-memory factory, and the EmbeddingError union (NoEmbeddingProviderError, UnknownEmbeddingModelError, DuplicateEmbeddingProviderError, AmbiguousDefaultProviderError). No I/O; the only state is the registry's in-memory map. No provider ships here — adapters implement EmbeddingProvider and are registered at boot.@kindgi/env-inmemory: Reference in-memoryEnvBindingadapter — dev + tests only; refuses to boot in production.@kindgi/env-schema: Machine-readable registry of the Kindgi runtime's operator-facing env vars. Single source of truth for boot-time validation (validateEnvForTarget), .env.example scaffolding (renderEnvExample), and tools or coding agents introspecting deployment config. Adding a new env var means adding one entry here — no drift between validation, docs, and .env.example generation.@kindgi/flow: Flow model + predicate DSL for Kindgi™. Defines the task-flow shape (nodes, edges, conditional edges, data-flow mappings) executed by the kernel. Pure — no I/O, no database, no runtime. Ships types, a JSON-schema-validated loader (loadFlow / defineFlow), a predicate evaluator and mapping resolver (evaluateExpr / resolveMapping), and the scheduler tick (schedulerTick) the kernel uses to pick the nodes ready for concurrent execution.@kindgi/guardrails: Runtime + CI enforcement of agent-behavior guardrails for Kindgi. Same declaration runs at runtime (halt / retry / escalate / log-only / compensate on violation) and in CI (fails the build) — no drift between test and prod. Zero-LLM checks (must-cite, never-call-tool, max-tool-calls, output-matches, tool-order, required-substring, forbidden-substring) are the default fast path; LLM-judge guardrails route via @kindgi/capabilities with explicit budget declarations. Execution strategies and action handlers are pluggable registries, and failed checks optionally emit compliance evidence.@kindgi/handler: Kindgi™ pack-author authoring surface. The types a pack author writes handlers against: NodeHandler (the function signature), NodeContext (what handlers receive at invocation — run scope, sibling outputs, waitForToken, authorize, clockNow, etc.), HandlerResult (structured return with optional stateDelta), HandlerRegistry (NodeId → NodeHandler map), LoopContext + LoopNodeOutput (loop-node shapes), plus WaitpointCancelledError (thrown by waitForToken when the wait is cancelled externally). Types plus that one error class — no other runtime code. Every runtime that executes Kindgi handlers implements this contract.@kindgi/handler-runtime: Runtime-side primitives for running a Kindgi pack's own code. Ships the pack service (pack-service, process entrypack-service-main) — a long-lived HTTP server that runs a pack's tool handlers and guardrail checks over pack protocol v2 (protocol), validating each tool call's input and output against the tool's JSON Schemas, with a local supervisor for development; and the build-time pack indexer (kindgi-index, process entrykindgi-index-main), which writes the pack'sindex.json.@kindgi/memory: Kindgi™ memory type surface. Public type contract for the memory subsystem: Fact (typed versioned record, Kind-A immutable or Kind-B cached-view), Retention (fact-level retention override), MemoryScope (where in the tenant/user/thread hierarchy a Fact lives), Source + SourceFreshness + SourceRefresh (external-source metadata for Kind-B facts). Also LogEntry + LOG_KINDS (hash-chained run log), RetrievalHit, the MemoryError variants, and MemoryQueryBinding (the data-access interface a binding implementation provides). Types and interfaces only — no runtime state. Storage, indexes, retrieval, and retention sweeps are provided by a binding implementation, such as the Postgres-backed one in the Kindgi runtime.@kindgi/pack-conformance: Conformance suite for pack services: a black-box HTTP and process test of pack protocol v2 and the pack index, run against any language's pack service and indexer over the same fixture pack. Kindgi's Node pack service and the Pythonkindgipackage both pass it.@kindgi/platform: Multi-tenant hierarchy primitives — the Tenant → Org → Team → Project + User type surface, theScopediscriminated access-boundary, binding interfaces for orgs, teams, projects, memberships, team-project grants and the tenant hierarchy, and reference in-memory adapters.@kindgi/policy-contract: Kindgi™ policy-contract type surface. Contract for the tenant policy catalog — Policy, PolicyKind + POLICY_KINDS, the PolicyRegistryBinding storage interface with its I/O shapes and PolicyPublishOutcome / PolicyUnregisterOutcome / PolicyReinstateVersionOutcome result unions, the PolicyExecutor / PolicyRegistry / PolicyEvalContext evaluation interfaces, and the specs of three kinds with their pure validators: retention (RetentionSpec, RETENTION_DOMAINS, validateRetentionSpec), tool-errors (ToolErrorsSpec, validateToolErrorsSpec) and hitl (HitlSpec, validateHitlSpec, combineHitlSpecs), plus validatePolicySpec(kind, spec). Types, interfaces, constants, validators and combinators — no runtime state, no implementations. Policy executors and storage bindings implement these interfaces; @kindgi/api routes and @kindgi/agents bind against them.@kindgi/provenance: Kindgi™ provenance type surface + pure DAG primitives. Public type contract for the provenance subsystem: Provenance (signed run DAG), ProvenanceBuilder (incremental DAG assembly interface), ProvenanceNode + ProvenanceEdge + NODE_KINDS + EDGE_KINDS, Signature, KeyProvider + KeyMaterial (caller-plugged key store interface), ProvenanceError variants (InvalidProvenanceError, UnknownKeyError, SigningNotSupportedError, SignatureVerificationError, MissingSignatureError, PersistenceError, ProvenanceNotFoundError). Pure functions: newBuilder (DAG builder factory), signProvenance + verifyProvenance + verifyExported (Ed25519 primitives against canonical bytes), exportProvenance + importProvenance (round-trippable JSON), signingBytes (canonical projection), wrap + unwrap + unwrapOrThrow (versioned envelope). Also ProvenanceEmitBinding — caller-plugged emit method that hides the concrete store behind an interface. Storage, queries, and key management are provided by binding and KeyProvider implementations, such as those in the Kindgi runtime.@kindgi/runtime: Kindgi™ runtime wire-vocabulary + binding interfaces. Public shape covering: RunStatus / RunResult / RunOptions / JournalEntry / JournalKind and all fanout/subgraph/iteration/step payload types; all kernel error shapes (KernelError, RunNotFoundError, HandlerMissingError, WaitpointError, etc.); run inputs and records (RunFlowInput / ResumeRunInput / StartRunParams, FlowResolver, HandlerResolver, ParentRunRef, KernelRunRecord, ListRunsInput); trigger schemas (Cron/Event/Webhook records + inputs + errors, plus TriggerRegistryBinding + RunFlowBinding + TRIGGER_KINDS); versioning envelope + wrap/unwrap; event-bus channel + KernelEventBusBinding; and the binding interfaces (RunBinding, SchedulerBinding, WaitpointBinding, RunRetentionBinding, umbrella KernelBinding) that deployments plug intocreateApp. Types + pure derivation functions — no runtime state, no dependency on a runtime implementation. The Kindgi runtime implements the bindings.@kindgi/sandbox: Kindgi™ sandbox contract and wire protocol. Types for the provider seam that sandbox adapters implement (SandboxProvider, Sandbox, SandboxSpec, SandboxCapabilities, KnownSandboxCapability, SandboxLimits, NetworkPolicy, SandboxLevel, HandlerInvocationMode, SandboxInvocationContext, HandlerRef, SnapshotHandle), process I/O (ProcessHandle, ProcessOpts, ProcessStdin, ExecOpts, ExecResult, ResourceUsage), and the SandboxError union (SandboxErrorCode; CancelledError, ConfigInvalidError, CreateCancelledError, InvalidSnapshotHandleError, LevelNotSupportedError, LimitsExceededError, OrphanedError, PauseNotSupportedError, ProviderError, RestoreNotSupportedError, SnapshotNotSupportedError, TimeoutError, UnhandledWorkerError) with pure constructors (createCancelled, levelNotSupported, providerError). Also the json-stdio invocation protocol: frame types (InvokeFrame, ResumeFrame, StdinFrame, OutputFrame, ErrorFrame, SuspendFrame, StdoutFrame, WireFrame, ProtocolContext, ProtocolError), pure encodeFrame / parseFrame / parseFrames, PROTOCOL_VERSION, SUSPEND_EXIT_CODE, DEFAULT_ENTRYPOINT_PATH, and the SandboxSuspensionRequest class. No runtime state. Adapters and handler dispatch live outside this package.@kindgi/schema: JSON Schema utilities for Kindgi. Loads specs, provides Ajv-based validation, extracts schema versions. Consumers validate incoming data against the wire contracts in @kindgi/specs.@kindgi/sdk: @kindgi/sdk — the authoring SDK for Kindgi™. Facade over the individual @kindgi/* packages + @kindgi/client. Unifies pack authoring (defineTool / defineCheck / defineAgent / defineFlow) and client callsites (createClient) behind three sub-paths: /define, /client, /types. Re-export facade; zero behavior.@kindgi/secrets-dotenv: Dev-modeSecretBindingover the project's own env files (.env, then.env.local, ordev.envFiles) — the same files, parsed the same way, as the app beside the pack — plus the one definition of which env files belong to a pack environment.KINDGI_*names are runtime config, never secrets. Not for production — no encryption, no audit, no versioning.@kindgi/specs: Canonical JSON Schemas (Draft 2020-12) for every Kindgi artifact kind — flow, agent, tool, capability, guardrail, policy, event, run event, memory, provenance, pack, compliance evidence, audit bundle, eval suite, discoverable entity. The wire contracts every SDK, runtime, and external tool validates against. Each schema is importable by name as@kindgi/specs/<name>.schema.json.@kindgi/testing: Test helpers for Kindgi apps and packages.createStubAppBindings()supplies every bindingcreateApprequires as a typed stub that throws a descriptiveStubBindingErrorif called — mount the API for contract / route-shape tests without a database or the Kindgi runtime.@kindgi/tools: Tool authoring shape + registry + invocation for Kindgi. A tool is a typed, effect-declared unit of work — the same definition runs in-process for one flow, over MCP for another. Pure — no kernel dependency; the kernel bridges tools to node handlers separately.@kindgi/types: Foundational TypeScript types shared across Kindgi. Branded IDs, timestamps, hashes, refs, Result, list filter / page shapes. Zero runtime dependencies; the only runtime export is the makeEnvName validator.