Developers

One call. Before the action.

Text, tools, and side effects stay in your agent. Vulnify sees who, what, where, and how many, and answers ALLOW, REVIEW, or BLOCK.

Install the SDK.

The Node and Python packages are published. npm install @vulnify/sdk includes the CLI. pip install vulnify installs the SDK, and pip install "vulnify[cli]" installs the Python CLI.

import { Vulnify } from '@vulnify/sdk';

const vulnify = new Vulnify({
  apiKey: process.env.VULNIFY_API_KEY,
});

await vulnify.guard(
  {
    agent: 'sales-copilot',
    action: 'EXPORT_DATA',
    resource: 'crm.contacts',
    destination: 'EXTERNAL_EMAIL',
    recordsAffected: 48120,
  },
  () => exportContacts(),
);

BLOCKResponse · 91 / 100

{
  "decision": "BLOCK",
  "riskScore": 91,
  "reasons": [
    "Bulk export of personal data",
    "Destination outside the policy"
  ]
}

npm · PyPI

Policies live in git.

The CLI calls GET /v1/policies, POST /v1/policies/apply, and POST /v1/policies/test. pull writes one YAML file per policy, apply sends those files, and test runs the cases. policies apply --dry-run plans the change and writes nothing. test --local sends the cases with the policy files in vulnify/policies. A failing case exits 1, so a CI job can run the command. Keep the YAML in git.

CLI and policies as code

npm install @vulnify/sdk
npx -p @vulnify/sdk vulnify policies pull --out vulnify/policies
npx -p @vulnify/sdk vulnify policies apply --dry-run
npx -p @vulnify/sdk vulnify test --local
pip install vulnify
pip install "vulnify[cli]"
vulnify policies pull --out vulnify/policies
vulnify policies apply --dry-run
vulnify test --local

What you send.

Authorize with a bearer key. The call goes to https://api.vulnify.io. The event carries agent, action, resource, destination, and a count, not the records. A retry sends an Idempotency-Key. A test key decides inside a sandbox and does not touch production credentials.

Fail closed

Unreachable means the action does not run, unless you choose fail open.

Score

A 0–100 score and the reasons come back with ALLOW, REVIEW, or BLOCK.

The secret stays in the vault.

The agent calls the API or SDK before the action and obeys the verdict. Or it uses the beta gateway, which decides and forwards the call, injecting the credential only on ALLOW. A fully transparent gateway, where the agent only changes its base URL, is not built yet.

API

Available. POST /v1/events from any language.

Node and Python SDKs

Available on npm and PyPI. npm install @vulnify/sdk includes the CLI. pip install vulnify installs the SDK. The Python CLI is pip install "vulnify[cli]".

Gateway

Beta. It decides and forwards. A transparent base-URL swap is not built yet.

Slack Beta

The hosted Slack app can approve or deny from the alert. An incoming webhook posts alerts and does not approve reviews. Slack in the docs

GitHub and Jira

Beta. The connectors exist. They need the customer’s own token.

Audit export

Available. Download the audit log as JSON or CSV from the app.