Skip to content

Connect your first agent in 15 minutes

Your workspace has been provisioned for you by Xybern. This page takes you from an empty workspace to an agent whose every action is authorised, in four steps. Nothing on this page needs help from Xybern.

Step 1, Mint an API key (2 minutes)

In the dashboard open Connect → SDK & keys → Mint key. Give it a name, keep the default scopes (verify, reason, vault), and copy the key. It is shown once.

export XYBERN_API_KEY=xb_live_…

Scopes

verify lets an agent ask for authorisation. approvals lets a key resolve escalations through the API and is never granted by default, so an agent can never approve its own escalation.

Step 2, Connect the agent

Pick the path that matches how your agent is built. All four go through the same authorisation engine and produce the same receipts.

pip install xybern
import xybern
xybern.auto.connect()   # observe mode: discovers your agents, registers each one,
                        # records every action, blocks nothing

Run your agent as normal. Within seconds it appears under Agents → Registry and its actions under Oversee → Authorisations.

Or leave the file untouched and start it through the CLI:

xybern login
xybern run --agent procurement-agent python agent.py

--agent gives the whole process one identity, with its tools as capabilities.

Python (explicit client):

from xybern import Xybern

xy = Xybern(agent_id="procurement-agent")
d = xy.authorize("purchase_order.create",
                 context={"amount": 750000, "currency": "SAR", "classification": "CONFIDENTIAL"})
if d.allowed:
    create_purchase_order()
elif d.escalated:
    if d.wait(timeout=900).allowed:     # blocks until a human decides in the dashboard
        create_purchase_order()

Or the REST call the SDKs make under the hood:

curl -X POST https://www.xybern.com/api/v1/enforce/intercept \
  -H "X-API-Key: $XYBERN_API_KEY" -H "Content-Type: application/json" \
  -d '{
    "agent_id": "procurement-agent",
    "action_type": "purchase_order.create",
    "action_content": "Create PO 4411 for SAR 750,000",
    "metadata": {"amount": 750000, "currency": "SAR", "classification": "CONFIDENTIAL"}
  }'

Response:

{"ok": true, "decision": "escalate", "decision_id": "enf_…", "escalation_id": "esc_…",
 "reasoning": "…", "vault_entry_id": "ve_…"}

decision is one of allow, block, escalate, terminate. Execute only on allow, or after an escalation is approved (GET /v1/enforce/escalations/<id>/status returns decision: "allow" while the approval is fresh).

TypeScript: npm install @xybern/sdk, then xybern.enforce.intercept({...}) and waitForEscalation().

Open Connect → MCP Gateway → Quick Connect. Enter the MCP server's URL, pick guard templates (GitHub, Postgres, Slack, filesystem, Stripe), and paste the generated snippet into your client. Every tools/call is authorised before it reaches the server.

Point your provider SDK at the Xybern gateway. Every model call is authorised, then forwarded.

OPENAI_BASE_URL=https://www.xybern.com/gateway/openai/v1
OPENAI_DEFAULT_HEADERS='{"X-Xybern-API-Key": "xb_live_…"}'

Or in Python, import xybern; xybern.auto_patch() before creating OpenAI / Anthropic / Bedrock clients.

Step 3, Write your first mandate (5 minutes)

Open Authority → Charter → New mandate and describe the outcome in plain language, for example:

Payments above SAR 500,000 need a human approval. Customer PII may never be sent to an external model.

Xybern compiles it into enforcement primitives, backtests it against the last 30 days of real decisions, and you save it as shadow (reports what it would have done) or active.

Step 4, Turn enforcement on

xybern enforce on          # or xybern.auto.connect(mode="enforce")

From now on block stops the action, escalate holds it for a human in Oversee → Escalations, and every decision is sealed as an Authorisation Receipt you can verify offline (Proof → Proof of Authorisation).

Running it inside your own network

Set XYBERN_BASE_URL to a self-hosted relay or your dedicated / sovereign deployment and nothing else changes:

export XYBERN_BASE_URL=http://relay.internal:8787/v1

See Self-Hosted Relay.