Limetry Central
Self-hosted · Action governance API

Stop irreversible agent side effects cold.

This node is the open-source Limetry evaluation server. Agents, MCP hosts, and the CLI call it to evaluate tool-call intents, return an outcome (allow, deny, or wait), and audit a scrubbed projection (minimal by default) — before an irreversible tool runs.

Evaluate before execute

POST an ActionIntent. Get allow, deny, or wait — plus reasons and a signed receipt. Audit stores a scrubbed projection (minimal by default)—not the full intent.

Audit you can tail

Every evaluation and recorded outcome becomes a structured event for operators and CI.

Engineer surfaces

Same contract as @limetry/sdk, @limetry/cli, and @limetry/mcp.

Available paths

Bearer tokens need matching scopes. JWT routes use operator login.

Method / path Auth Purpose
GET / none This landing page
GET /openapi.yaml none OpenAPI YAML document
GET /openapi.json none OpenAPI JSON document
GET /openapi none Swagger UI
GET /health none Health check
POST /v1/actions/record bearer · API key Record action outcome
GET /v1/audit bearer · API key List audit events
PUT /v1/policies/{id} bearer · API key Upsert an action policy
POST /v1/policy/evaluate bearer · API key Evaluate an action intent

Try evaluate

Use @limetry/cli against this API. Credentials are saved to ~/.limetry/config.json (not shell exports). Invalid JSON bodies return {"error":"invalid_json"} — never HTML error pages.

# 0. Install the CLI (once)
npm install -g @limetry/cli

# 1. Connect — choose Self-hosted / OSS, base URL https://api.limetry.dev
#    Bearer token: your server LIMETRY_BEARER_TOKEN (deploy secret or local .env)
limetry setup

# 2. Health check
curl -s https://api.limetry.dev/health

# 3. Apply a slim policy (allow GET, deny POST to prod)
limetry policy apply --agent-id demo \
  --allow http_get --deny http_post \
  --block-resource 'https://prod.example.com/*'

# 4. Evaluate a denied POST (use policy_id from step 3 output)
cat <<'EOF' | limetry eval
{
  "intent_id": "550e8400-e29b-41d4-a716-446655440001",
  "policy_id": "PASTE_POLICY_ID_FROM_APPLY",
  "agent_id": "demo",
  "action_type": "http_post",
  "resource": "https://prod.example.com/deploy",
  "issued_at": "2026-01-01T00:00:00.000Z"
}
EOF

# 5. Optional: tail privacy-safe audit
limetry audit tail --limit 5