Evaluate before execute
POST an ActionIntent. Get allow, deny, or wait — plus reasons and a signed receipt. Audit stores a scrubbed projection (minimal by default)—not the full intent.
This node is the open-source Limetry evaluation server. Agents, MCP hosts, and the CLI call it to evaluate tool-call intents, return an outcome (allow, deny, or wait), and audit a scrubbed projection (minimal by default) — before an irreversible tool runs.
POST an ActionIntent. Get allow, deny, or wait — plus reasons and a signed receipt. Audit stores a scrubbed projection (minimal by default)—not the full intent.
Every evaluation and recorded outcome becomes a structured event for operators and CI.
Same contract as @limetry/sdk, @limetry/cli, and @limetry/mcp.
Bearer tokens need matching scopes. JWT routes use operator login.
| Method / path | Auth | Purpose |
|---|---|---|
GET / |
none | This landing page |
GET /openapi.yaml |
none | OpenAPI YAML document |
GET /openapi.json |
none | OpenAPI JSON document |
GET /openapi |
none | Swagger UI |
GET /health |
none | Health check |
POST /v1/actions/record |
bearer · API key | Record action outcome |
GET /v1/audit |
bearer · API key | List audit events |
PUT /v1/policies/{id} |
bearer · API key | Upsert an action policy |
POST /v1/policy/evaluate |
bearer · API key | Evaluate an action intent |
With the server running and LIMETRY_BEARER_TOKEN set, upsert a policy then evaluate a denied action:
curl -s https://test.limetry.dev/health
curl -s -X PUT https://test.limetry.dev/v1/policies/$POLICY_ID \
-H "Authorization: Bearer $LIMETRY_BEARER_TOKEN" \
-H "Content-Type: application/json" \
-d '{"policy":{ ... ActionPolicy ... }}'
curl -s -X POST https://test.limetry.dev/v1/policy/evaluate \
-H "Authorization: Bearer $LIMETRY_BEARER_TOKEN" \
-H "Content-Type: application/json" \
-d '{"policy_id":"'"$POLICY_ID"'","intent":{ ... ActionIntent ... }}'