Docs

Quickstart, the live API reference, and SDK usage. Every command below was run locally against this repo before being written down here.

Quickstart

1. Boot the stack

Zero-config route, for looking around (seeded demo users, file-backed ledger, no Postgres):

docker compose --profile local-demo up local-demo

Real production boot (Postgres-backed, `PRODUCTION` mode):

export ACTASEAL_SIGNING_KEY=$(openssl rand -hex 32)
export ACTASEAL_ADMIN_USERNAME=admin
export ACTASEAL_ADMIN_PASSWORD='choose-a-real-password'
docker compose up --build

The production route boots with no policy pack bound -- /gateway/preflight returns MISSING_POLICY_REFERENCE until you load one via the config-file route (see README-DEPLOY.md in the repo for the full path, including the Postgres buildx-version prerequisite).

2. First-run setup

Open http://localhost:8000 and log in with the admin credentials above (env-var route) or through OIDC (config-file route). GET /readyz returning {"status":"ready"} means the process, ledger, and signing key are healthy -- it does not by itself mean a policy is bound.

3. First receipt

With a policy bound, POST /gateway/preflight mints a signed receipt on every decision. A runnable end-to-end example, including a real signed receipt with a bound terms_hash, is included with every deployment.

4. Verify offline

actaseal verify-receipt --receipt receipt.json --ledger ledger.json

Or, with no ActaSeal installation at all -- only the public key and the standalone verifier -- use verify.actaseal.com.

API reference

Generated directly from the live FastAPI app's own OpenAPI schema (never hand-written, so it cannot drift from the real routes) -- full API reference.

SDKs

Python

from actaseal.sdk.thin_client import ActaSeal

guard = ActaSeal("https://gateway.example.com", api_key="...", policy_id="refunds_policy")
decision = guard.guard({"action_type": "refund_request", "money": {"amount": "50.00", "currency": "USD"}})

TypeScript

The TypeScript SDK is not published to npm yet. It is installed from a tarball we provide, not with npm install. The import line below is what the API looks like once it resolves, not something you can run today. Ask and we will send you a tarball.

import { ActaSeal, ActaSealBlocked, ActaSealApprovalRequired } from "@actaseal/sdk";

const guard = new ActaSeal("https://gateway.example.com", { apiKey: process.env.ACTASEAL_API_KEY! });
const sendRefund = guard.wrap(
  (amount) => fetch("/internal/refund", { method: "POST", body: amount }),
  (amount) => ({ action_type: "refund_request", money: { amount, currency: "USD" } }),
);

LangChain / LangGraph

from actaseal.sdk.integrations.langchain_tools import guard_langchain_tool

guarded_tool = guard_langchain_tool(actaseal, my_refund_tool, action_type="refund_request")
# BLOCK -> langchain_core.tools.ToolException (surfaced to the model as a tool error)
# APPROVAL_REQUIRED -> ActaSealApprovalRequired re-raised for your own retry/escalation logic

OpenAI Agents SDK

from actaseal.sdk.integrations.openai_agents_tools import guard_openai_agents_tool

guarded_tool = guard_openai_agents_tool(actaseal, my_refund_tool, action_type="refund_request")

Both adapters are optional imports -- actaseal imports cleanly with neither framework installed.

Standards work

draft-xg-payment-dispute-profile-00 -- see the proof section on the landing page for the full list of public standards work and links.