io.github.vassiliylakhonin/vizier

Vizier

Deterministic authorization for one proposed AI agent action, returned with a signed receipt.

0.5.7
Version
remote
Transport
1
Tools

Security review

Review passed

Reviewed 1d ago.

  • tools: 1 tools scanned
  • metadata: scanned

No findings.

Tools (1)

  • vizier_verify_action

    Evaluate whether an AI agent should be allowed to perform a proposed action. Call vizier_verify_action immediately before an AI agent executes an external action. Signed grant mode: required. Anonymous calls are evaluation-only and never grant ALLOW. An API key authenticates the integration; it is not principal delegation. In required mode, missing grants return GRANT_REQUIRED. An invalid deployment policy returns GRANT_POLICY_MISCONFIGURED; the operator must repair configuration. The principal owner generates an ES256 key outside the agent. Ask the operator to register only its public JWK under the principal id in VIZIER_PRINCIPAL_KEYS; check /docs delegation.principal_keys_valid and registered_principals. The owner issues a short-lived compact ES256 grant bound to this principal, agent and exact authority. Keep the private key outside prompts, requests and the agent's control. Do not fabricate a grant or reuse the synthetic example as authority. Submit the real grant with the verific