Limetry Central
Self-hosted · Action governance API

Stop irreversible agent side effects cold.

This node is the open-source Limetry evaluation server. Agents, MCP hosts, and the CLI call it to evaluate tool-call intents, return an outcome (allow, deny, or wait), and audit a scrubbed projection (minimal by default) — before an irreversible tool runs.

Evaluate before execute

POST an ActionIntent. Get allow, deny, or wait — plus reasons and a signed receipt. Audit stores a scrubbed projection (minimal by default)—not the full intent.

Audit you can tail

Every evaluation and recorded outcome becomes a structured event for operators and CI.

Engineer surfaces

Same contract as @limetry/sdk, @limetry/cli, and @limetry/mcp.

Available paths

Bearer tokens need matching scopes. JWT routes use operator login.

Method / path Auth Purpose
GET / none This landing page
GET /openapi.yaml none OpenAPI YAML document
GET /openapi.json none OpenAPI JSON document
GET /openapi none Swagger UI
GET /health none Health check
POST /v1/actions/record bearer · API key Record action outcome
GET /v1/audit bearer · API key List audit events
PUT /v1/policies/{id} bearer · API key Upsert an action policy
POST /v1/policy/evaluate bearer · API key Evaluate an action intent

Try evaluate

With the server running and LIMETRY_BEARER_TOKEN set, upsert a policy then evaluate a denied action:

curl -s https://test.limetry.dev/health

curl -s -X PUT https://test.limetry.dev/v1/policies/$POLICY_ID \
  -H "Authorization: Bearer $LIMETRY_BEARER_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"policy":{ ... ActionPolicy ... }}'

curl -s -X POST https://test.limetry.dev/v1/policy/evaluate \
  -H "Authorization: Bearer $LIMETRY_BEARER_TOKEN" \
  -H "Content-Type: application/json" \
  -d '{"policy_id":"'"$POLICY_ID"'","intent":{ ... ActionIntent ... }}'