Naar de inhoud

Labs · preview

Controleer vóór je AI-agent handelt

Jithox controleert een actie voordat je AI-agent ze uitvoert. Beschrijf wat de agent wil doen, krijg één duidelijk antwoord en de veilige volgende stap. Jithox controleert; het voert nooit uit.

Hier wordt niets uitgevoerd

De beslissing is een vaste regel, geen model, en ze draait in je browser met dezelfde code als de API. Versturen, publiceren, betalen, indienen, testen en wijzigen blijven bij je officiële connector, na jouw goedkeuring.

Geen account. Er wordt niets verstuurd, niets opgeslagen en niets uitgevoerd.

Jouw beslissing

Beoordeeld op de vaste klok 2026-09-10T12:00:00Z, dus het antwoord is elke keer hetzelfde.

groen vinkje

Veilig voor te bereiden

Je agent mag dit voorbereiden. Alleen voorbereiding: als de actie de workspace verlaat, heeft de eigenlijke stap nog een officiële connector nodig, na jouw goedkeuring.

Alleen voorbereiding. Deze beslissing is geen toestemming om uit te voeren.

Waarom

  • Niets staat in de weg.

Wat nog ontbreekt

  • Niets.

Wat je agent veilig mag voorbereiden

  • Make the change in the workspace.
  • Run the local tests.

Wat niet mag worden uitgevoerd

  • Nothing to execute: this action has no external step.
Budget:
No money is involved in this action.
Goedkeuring:
niet vereist
Geldig tot:
2026-09-10T14:00:00.000Z
Policyversie:
jithox.agent-action-policy/v1
Receipt:
unsigned, aan de hash gebonden · b7e5ec1dc8fd7f6a
Bewijsverwijzingen:
geen meegegeven · Preflight-ID apf_319e77ea60aa43d0
Action hash:
319e77ea60aa43d0fa263d7df6cb436767105dc68142f5ded916b21079d79a09
Open de developer-gids

Preflight klaar: Veilig voor te bereiden. Er is niets uitgevoerd.

Jithox controleert; het voert nooit uit. Status: preview local build.

Developer-details

Het verzoek precies zoals de API het ontvangt, het resultaat zodra je een beslissing hebt, en dezelfde oproep als curl. Niets boven deze lijn heeft dit nodig.

{
  "request": {
    "schemaVersion": "jithox.agent-action-preflight-request/v1",
    "action": {
      "type": "modify_local_files",
      "target": {
        "kind": "proposal_draft",
        "id": "opportunity:EXAMPLE-4711"
      },
      "summary": "Draft the proposal text and the price table."
    },
    "agent": {
      "id": "first-cash-bot",
      "client": "chatgpt"
    },
    "owner": {
      "ref": "owner:jithox",
      "workspaceRef": "ws:first-cash"
    },
    "requestedPermissions": [
      "read",
      "edit_local_files"
    ],
    "dataClassification": "internal",
    "money": null,
    "externalSideEffect": false,
    "reversible": "yes",
    "authority": {
      "kind": "none"
    },
    "humanApproval": null,
    "idempotencyKey": "first-cash-draft-4711-2026-09-10",
    "requestedExpiresAt": "2026-09-10T14:00:00Z"
  },
  "result": {
    "schemaVersion": "jithox.agent-action-preflight-result/v1",
    "policyVersion": "jithox.agent-action-policy/v1",
    "status": "preview_local_build",
    "preflightId": "apf_319e77ea60aa43d0",
    "decision": "ALLOWED_TO_PREPARE",
    "reasonCodes": [],
    "reasons": [],
    "missingRequirements": [],
    "allowedPreparationSteps": [
      "Make the change in the workspace.",
      "Run the local tests."
    ],
    "prohibitedExecutionSteps": [
      "Nothing to execute: this action has no external step."
    ],
    "approvalRequired": false,
    "approvalStatus": "not_required",
    "budget": {
      "relevant": false,
      "maxAmountMinor": null,
      "currency": null,
      "standingBudgetMinor": null,
      "withinStandingBudget": null,
      "note": "No money is involved in this action."
    },
    "expiresAt": "2026-09-10T14:00:00.000Z",
    "actionHash": "319e77ea60aa43d0fa263d7df6cb436767105dc68142f5ded916b21079d79a09",
    "evidence": {
      "supplied": [],
      "preflightId": "apf_319e77ea60aa43d0"
    },
    "replayProtection": {
      "scope": "process_memory",
      "durable": false,
      "idempotencyKey": "first-cash-draft-4711-2026-09-10"
    },
    "receipt": {
      "kind": "agent_action_preflight_receipt",
      "signature": "unsigned_hash_bound",
      "algorithm": "sha256-canonical-json",
      "digest": "b7e5ec1dc8fd7f6a5499f1cc2aa522db217b368d50a443d7721494e4d035e63f",
      "boundTo": {
        "actionHash": "319e77ea60aa43d0fa263d7df6cb436767105dc68142f5ded916b21079d79a09",
        "decision": "ALLOWED_TO_PREPARE",
        "policyVersion": "jithox.agent-action-policy/v1",
        "evaluatedAt": "2026-09-10T12:00:00.000Z",
        "preflightId": "apf_319e77ea60aa43d0"
      },
      "note": "This receipt is NOT signed. It is bound by a sha256 digest over the canonical decision; anyone can recompute it. A signed receipt needs the fleet's Ed25519 key, which this website does not hold."
    },
    "executed": false,
    "evaluatedAt": "2026-09-10T12:00:00.000Z"
  }
}
curl -s https://jithox.com/api/agent-preflight/v1/evaluate \
  -H 'content-type: application/json' \
  -d '{"schemaVersion":"jithox.agent-action-preflight-request/v1","action":{"type":"send_message","target":{"kind":"email","id":"customer:EXAMPLE-1"},"summary":"Reply to the customer's question."},"agent":{"id":"my-agent","client":"claude"},"owner":{"ref":"owner:me"},"requestedPermissions":["read","draft_messages","send_external_messages"],"dataClassification":"internal","money":null,"externalSideEffect":true,"reversible":"no","authority":{"kind":"none"},"humanApproval":null,"idempotencyKey":"reply-customer-1-2026-09-10","requestedExpiresAt":"2026-09-10T14:00:00Z"}'

Jithox controleert een actie voordat je AI-agent ze uitvoert.

  1. 1. Beschrijf de actie

    Kies wat de agent wil doen, zeg waar en voor wie, en wat er kan gebeuren.

  2. 2. Controleer toestemming, risico en budget

    Jithox vergelijkt dat met de rechten, de bevoegdheid, het budget en de goedkeuring die al bestaan.

  3. 3. Geef je agent alleen de veilige volgende stap

    Eén duidelijk antwoord, met wat mag worden voorbereid en wat op jou moet wachten.

Zo ziet dat eruit

  • Draft een e-mail, maar verstuur ze niet.
  • Maak een productvermelding, maar publiceer ze niet.
  • Bereid een Freelancer-voorstel voor, maar dien het niet in.
  • Inspecteer een geautoriseerde ZIP, maar scan geen extern doelwit.
  • Bereid een aankoop voor, maar betaal niet.

Hoe de vier eigen Jithox-teams het gebruiken

Dezelfde fixtures als de API en de tests, beoordeeld op een vaste klok. Niets hiervan werd gepubliceerd, ingediend, getest of betaald.

Commerce

  • Buy something: 2 × EXAMPLE-thermal-label-printer at EUR 89.00

    The Commerce bot found the printer, the merchant's price quote and the shipping and tax lines. Buying is irreversible and moves money, so the owner approves the exact total first. Preparing the cart and the checkout link is all the bot may do until then.

    oranje uitroeptekenJouw goedkeuring is vereist

    external_execution_unsupported · approval_missing · data_classification_requires_approval

    Open dit voorbeeld

  • Buy something above the standing budget

    The same purchase, but the maximum total the bot asks for exceeds what the standing grant allows. No approval can rescue that: the request is blocked and the bot must come back with a smaller total or a new grant.

    rood kruisGeblokkeerd

    external_execution_unsupported · budget_exceeded · approval_missing · data_classification_requires_approval

    Open dit voorbeeld

  • Publish a EUR 29 product on Payhip

    The Commerce bot has assembled the listing. Publishing puts a price in front of the public, so the owner approves the exact listing hash first.

    oranje uitroeptekenJouw goedkeuring is vereist

    external_execution_unsupported · no_standing_budget · approval_missing · reversibility_unknown

    Open dit voorbeeld

First Cash

  • Prepare a freelance proposal

    Drafting a proposal changes nothing outside the workspace, so the bot may prepare it now.

    groen vinkjeVeilig voor te bereiden

    Open dit voorbeeld

  • Submit the proposal

    Submission reaches a real client and cannot be unsent; it waits for the owner's approval of that exact submission.

    oranje uitroeptekenJouw goedkeuring is vereist

    external_execution_unsupported · approval_missing · irreversible_requires_approval

    Open dit voorbeeld

Security

  • Inspect a customer's ZIP offline

    Inspection is allowed only because the customer's scope is recorded and immutable; nothing live is touched.

    groen vinkjeVeilig voor te bereiden

    Open dit voorbeeld

  • Test a customer target without authorization

    No standing grant with a recorded scope and expiry exists, so external testing is blocked outright.

    rood kruisGeblokkeerd

    external_execution_unsupported · authority_missing · approval_missing · reversibility_unknown · data_classification_requires_approval

    Open dit voorbeeld

Growth

  • Draft a social post

    A draft stays in the workspace, so the Growth bot may prepare it.

    groen vinkjeVeilig voor te bereiden

    Open dit voorbeeld

  • Publish the post automatically

    The bot holds no publish permission and no standing grant, so automatic publication is blocked, not merely queued for approval.

    rood kruisGeblokkeerd

    permission_missing · external_execution_unsupported · approval_missing · reversibility_unknown

    Open dit voorbeeld

Wat op deze pagina waar is

  • Preflight voert niets uit.
  • Een voorbereidingsbeslissing is geen toestemming om uit te voeren.
  • Receipts zijn op dit moment unsigned.
  • Voer nooit een credential in.
  • Niet te controleren is geen goedkeuring.
  • Een gewijzigde actie krijgt een andere actionHash.
  • Externe acties vereisen aparte bevoegdheid.

Prijs: de interactieve en lokale preflight is gratis. API-prijzen zijn niet gepubliceerd; in deze build wordt niets aangerekend. Jithox controleert; het voert nooit uit. Status: preview local build.

Met een teamplan

In Team Builder (Labs) kan elk teamplan deze preflight vereisen vóór elke externe actie; teams met externe acties vereisen ze standaard, en het plan exporteert de policyconfiguratie.

Open Team Builder (Labs)

Voor developers en AI-agents

Drie geversioneerde, compute-only routes over één gesloten schema. Dezelfde regel die je browser net uitvoerde.

HTTP API

GET /api/agent-preflight/v1/schema
Schemas, action types, decisions, reason codes, limits, MCP tool contract, client exports. public, max-age=300.
POST /api/agent-preflight/v1/evaluate
One planned action in; one bounded decision with reasons, missing requirements and a hash-bound receipt out. no-store.
GET /api/agent-preflight/v1/fixtures
The seven team demonstrations with their evaluated results. public, max-age=300.

Gesloten vocabularia

decisions
ALLOWED_TO_PREPARE · HUMAN_APPROVAL_REQUIRED · BLOCKED · UNAVAILABLE
actionTypes
read_data · modify_local_files · inspect_offline_artifact · send_message · publish_content · publish_product · purchase · refund · submit_proposal · accept_contract · security_test_external · change_production
dataClassifications
public · internal · confidential · personal · payment
reversibility
yes · no · unknown
authorityKinds
none · owner_instruction · standing_grant
agentClients
claude · chatgpt · gemini · grok_cursor · generic_mcp · generic_http · other
clientExportStatuses
CERTIFIED · CONFIG_READY · NOT_CERTIFIED · MCP_HOST_PENDING

De twaalf actietypes

  • read_data · Gegevens lezen · local · authority none
  • modify_local_files · Lokale bestanden wijzigen · local · authority none
  • inspect_offline_artifact · Een offline bestand inspecteren · local · authority required
  • send_message · Een bericht versturen · external · authority none
  • publish_content · Inhoud publiceren · external · authority none
  • publish_product · Een product publiceren · external · money · authority required
  • purchase · Iets kopen · external · money · authority required
  • refund · Een terugbetaling doen · external · money · authority required
  • submit_proposal · Een voorstel indienen · external · authority none
  • accept_contract · Een contract aanvaarden · external · money · authority required
  • security_test_external · Een systeem op zwakke plekken testen · external · authority standing grant required
  • change_production · Een live systeem wijzigen · external · authority required

Voorbeeld

VoorbeeldverzoekBuy something: 2 × EXAMPLE-thermal-label-printer at EUR 89.00

{
  "schemaVersion": "jithox.agent-action-preflight-request/v1",
  "action": {
    "type": "purchase",
    "target": {
      "kind": "merchant_order",
      "id": "EXAMPLE-shop|TLP-2026|v2026.09"
    },
    "summary": "Buy 2 × EXAMPLE thermal label printer (product version 2026.09) from EXAMPLE-shop.example: item EUR 89.00 each, shipping EUR 6.90, VAT EUR 38.83 (21%), total EUR 223.73; maximum total EUR 230.00; refundable within 14 days per the merchant's terms."
  },
  "agent": {
    "id": "commerce-bot",
    "client": "claude"
  },
  "owner": {
    "ref": "owner:jithox",
    "workspaceRef": "ws:commerce"
  },
  "requestedPermissions": [
    "read",
    "spend_money"
  ],
  "dataClassification": "payment",
  "money": {
    "maxAmountMinor": 23000,
    "currency": "EUR"
  },
  "externalSideEffect": true,
  "reversible": "yes",
  "authority": {
    "kind": "standing_grant",
    "ref": "grant:commerce-supplies-2026-q3",
    "scope": "Office and shipping supplies from approved merchants",
    "expiresAt": "2026-09-30T00:00:00Z",
    "budget": {
      "maxAmountMinor": 50000,
      "currency": "EUR"
    }
  },
  "humanApproval": null,
  "idempotencyKey": "commerce-buy-TLP-2026-09-10",
  "requestedExpiresAt": "2026-09-10T14:00:00Z",
  "evidence": [
    {
      "id": "ev-merchant-listing",
      "kind": "merchant_listing",
      "ref": "artifact:listing-TLP-2026"
    },
    {
      "id": "ev-price-quote",
      "kind": "price_quote",
      "ref": "artifact:quote-TLP-2026-09-10"
    },
    {
      "id": "ev-cancellation-terms",
      "kind": "merchant_terms",
      "ref": "artifact:terms-EXAMPLE-shop"
    }
  ]
}

VoorbeeldantwoordBeoordeeld op de vaste klok 2026-09-10T12:00:00Z, dus het antwoord is elke keer hetzelfde.

{
  "ok": true,
  "status": "preview_local_build",
  "result": {
    "schemaVersion": "jithox.agent-action-preflight-result/v1",
    "policyVersion": "jithox.agent-action-policy/v1",
    "status": "preview_local_build",
    "preflightId": "apf_302c33f5fbddad3c",
    "decision": "HUMAN_APPROVAL_REQUIRED",
    "reasonCodes": [
      "external_execution_unsupported",
      "approval_missing",
      "data_classification_requires_approval"
    ],
    "reasons": [
      {
        "code": "external_execution_unsupported",
        "message": "Jithox does not execute external actions. This preflight can allow preparation and bind an approval; the execution step stays with an official connector after approval."
      },
      {
        "code": "approval_missing",
        "message": "\"Buy something\" has an external side effect: the owner must approve this exact action (its hash)."
      },
      {
        "code": "data_classification_requires_approval",
        "message": "The action touches payment data."
      }
    ],
    "missingRequirements": [
      {
        "code": "approval_missing",
        "requirement": "Ask the owner to approve action hash 302c33f5fbddad3c912b04809f3016004e0c1ea3bb1f1664f2d8a68b5fa2dc7c before the expiry."
      }
    ],
    "allowedPreparationSteps": [
      "Assemble the exact item, price, fees, currency and cancellation terms.",
      "Compute the complete total."
    ],
    "prohibitedExecutionSteps": [
      "Placing the order. (never here; only through an official connector after approval)",
      "Paying. (never here; only through an official connector after approval)"
    ],
    "approvalRequired": true,
    "approvalStatus": "missing",
    "budget": {
      "relevant": true,
      "maxAmountMinor": 23000,
      "currency": "EUR",
      "standingBudgetMinor": 50000,
      "withinStandingBudget": true,
      "note": "Within the standing budget; the owner still approves this exact action."
    },
    "expiresAt": "2026-09-10T14:00:00.000Z",
    "actionHash": "302c33f5fbddad3c912b04809f3016004e0c1ea3bb1f1664f2d8a68b5fa2dc7c",
    "evidence": {
      "supplied": [
        "ev-merchant-listing",
        "ev-price-quote",
        "ev-cancellation-terms"
      ],
      "preflightId": "apf_302c33f5fbddad3c"
    },
    "replayProtection": {
      "scope": "process_memory",
      "durable": false,
      "idempotencyKey": "commerce-buy-TLP-2026-09-10"
    },
    "receipt": {
      "kind": "agent_action_preflight_receipt",
      "signature": "unsigned_hash_bound",
      "algorithm": "sha256-canonical-json",
      "digest": "55b77b2e19fb415ec2a24090627e57f1498f566242f3174af860206d6a803ea2",
      "boundTo": {
        "actionHash": "302c33f5fbddad3c912b04809f3016004e0c1ea3bb1f1664f2d8a68b5fa2dc7c",
        "decision": "HUMAN_APPROVAL_REQUIRED",
        "policyVersion": "jithox.agent-action-policy/v1",
        "evaluatedAt": "2026-09-10T12:00:00.000Z",
        "preflightId": "apf_302c33f5fbddad3c"
      },
      "note": "This receipt is NOT signed. It is bound by a sha256 digest over the canonical decision; anyone can recompute it. A signed receipt needs the fleet's Ed25519 key, which this website does not hold."
    },
    "executed": false,
    "evaluatedAt": "2026-09-10T12:00:00.000Z"
  },
  "executed": false,
  "stored": false
}

Reason codes

unknown_action_type
Het actietype is geen van de twaalf bekende types.
target_missing
De actie noemt geen doel.
expiry_invalid
De gevraagde geldigheid is geen geldige datum en tijd.
expiry_in_past
De gevraagde geldigheid ligt al in het verleden.
expiry_clamped
De gevraagde geldigheid was langer dan het maximum en is ingekort.
permission_missing
Een recht dat deze actie nodig heeft, is niet gevraagd.
permission_excessive
Er zijn meer rechten gevraagd dan deze actie nodig heeft.
external_execution_unsupported
Jithox voert geen externe acties uit; de uitvoeringsstap blijft bij een officiële connector na goedkeuring.
authority_missing
Geen instructie of toestemming staat deze actie toe.
authority_expired
De instructie of toestemming is verlopen of heeft geen geldige vervaldatum.
authority_scope_missing
De toestemming heeft geen scope.
authority_scope_not_immutable
De scope moet eerst als onveranderlijk worden vastgelegd.
budget_missing
Bij de actie komt geld kijken, maar er is geen maximumbedrag en valuta opgegeven.
budget_exceeded
Het maximumbedrag ligt boven het doorlopende budget.
currency_mismatch
De valuta komt niet overeen met het doorlopende budget, of er is een bedrag opgegeven voor een actie zonder geld.
no_standing_budget
Er is geen doorlopend budget, dus elk bedrag heeft de goedkeuring van de eigenaar voor exact deze actie nodig.
irreversible_requires_approval
De actie kan niet worden teruggedraaid zodra ze is uitgevoerd.
reversibility_unknown
Of de actie kan worden teruggedraaid, is onbekend.
data_classification_requires_approval
De actie raakt gevoelige gegevens.
approval_missing
De eigenaar moet exact deze actie goedkeuren.
approval_expired
De goedkeuring is verlopen of heeft geen geldige vervaldatum.
approval_hash_mismatch
De goedkeuring hoort bij een andere actie.
approval_not_yet_valid
De goedkeuring begint pas in de toekomst.
approval_valid
De eigenaar keurde exact deze actie goed.
duplicate_action
Deze actiesleutel is al gebruikt voor een andere actie.
dedupe_store_unavailable
De replay-store antwoordde niet, dus een dubbele actie kan niet worden uitgesloten.
evidence_missing
Voeg de offerte, factuur, vermelding of het contract toe waar het bedrag vandaan komt.

actionHash

  • sha256 over de canonieke JSON van: policyversie, actietype, doel, agent-id, eigenaarsverwijzing, gesorteerde rechten, dataclassificatie, geld, extern neveneffect, omkeerbaarheid, soort, verwijzing en scope van de bevoegdheid, en de idempotencyKey.
  • De gevraagde vervaldatum, de goedkeuring en het bewijs vallen buiten de hash: ze kunnen veranderen zonder de actie te veranderen.
  • Elke wijziging binnen de hash is een andere actie en heeft een eigen goedkeuring nodig.

Goedkeuringsbinding

  • humanApproval.actionHash moet gelijk zijn aan de actionHash van het verzoek, anders is de beslissing BLOCKED met approval_hash_mismatch.
  • approvedAt mag niet in de toekomst liggen; expiresAt moet een geldig tijdstip na nu zijn.
  • Een geldige goedkeuring maakt van HUMAN_APPROVAL_REQUIRED een ALLOWED_TO_PREPARE. Ze staat nooit uitvoering toe: de uitvoeringsstap blijft onder prohibitedExecutionSteps.

Replayregels

  • Eén idempotencyKey per eigenaar claimt één actionHash voor de looptijd van de controle.
  • Zelfde sleutel, zelfde hash: idempotent, identiek antwoord. Zelfde sleutel, andere hash: BLOCKED met duplicate_action.
  • Replay-store onbereikbaar: UNAVAILABLE met dedupe_store_unavailable, nooit een toestemming. De scope van de store staat in replayProtection.

Receipt

kind, signature (unsigned_hash_bound), algorithm, digest, boundTo {actionHash, decision, policyVersion, evaluatedAt, preflightId}, note. De digest is sha256 over het canonieke boundTo-object en kan door iedereen worden herberekend.

This receipt is NOT signed. It is bound by a sha256 digest over the canonical decision; anyone can recompute it. A signed receipt needs the fleet's Ed25519 key, which this website does not hold.

Limieten

  • 60 evaluaties per minuut per herkomst
  • 32768 bytes per verzoekbody
  • hoogstens 10 bewijsverwijzingen
  • een controle is hoogstens 24 uur geldig; langere verzoeken worden ingekort
  • hoogstens 9 gevraagde rechten

Foutstatussen

invalid_body
400 — de body is geen JSON.
payload_too_large
413 — de body is groter dan de payloadlimiet.
invalid_input
400 — de body voldoet niet aan het gesloten verzoekschema; het antwoord noemt het pad.
unknown_action_type
400 — action.type is geen van de twaalf types.
secret_detected
400 — een veld lijkt op een sleutel, token of private key; niets ervan wordt teruggegeven.
personal_data_rejected
400 — het doel of de samenvatting bevat een e-mailadres, telefoonnummer of bankrekening.
rate_limited
429 met Retry-After — meer dan de limiet per minuut vanaf één herkomst.

Kopieerbare configuratie

Een snippet is geen gecertificeerde client. Elke integratie draagt haar eerlijke label.

CERTIFIED
:
in deze build end-to-end uitgevoerd tegen het echte endpoint, met bewijs
CONFIG_READY
:
de configuratie is volledig en gevalideerd; ze is in deze build nog niet end-to-end door een echte client uitgevoerd
NOT_CERTIFIED
:
geprobeerd en niet bewezen, of niet geprobeerd
MCP_HOST_PENDING
:
het contract is volledig; de MCP-host die het zou serveren bestaat nog niet
  • Claude Code CONFIG_READY

    Add the rule below to the project's CLAUDE.md. Claude Code runs the curl through its Bash tool and reads the decision before it drafts or asks for approval.

    CLAUDE.md
    ## Jithox Agent Action Preflight
    
    Before any action that sends, publishes, buys, submits, accepts, tests or changes something outside the workspace:
    1. POST the planned action to https://jithox.com/api/agent-preflight/v1/evaluate (schema: https://jithox.com/api/agent-preflight/v1/schema).
    2. Act only on ALLOWED_TO_PREPARE. On HUMAN_APPROVAL_REQUIRED, show the owner the actionHash and stop. On BLOCKED or UNAVAILABLE, stop and report the reason codes.
    3. Never execute the external step yourself; Jithox does not execute either. Hand an approved hash to the official connector.
    4. Never put a credential, key or personal detail in the request; the endpoint refuses them.
    
    Command:
    
    ```bash
    curl -s https://jithox.com/api/agent-preflight/v1/evaluate \
      -H 'content-type: application/json' \
      -d '{"schemaVersion":"jithox.agent-action-preflight-request/v1","action":{"type":"send_message","target":{"kind":"email","id":"customer:EXAMPLE-1"},"summary":"Reply to the customer's question."},"agent":{"id":"my-agent","client":"claude"},"owner":{"ref":"owner:me"},"requestedPermissions":["read","draft_messages","send_external_messages"],"dataClassification":"internal","money":null,"externalSideEffect":true,"reversible":"no","authority":{"kind":"none"},"humanApproval":null,"idempotencyKey":"reply-customer-1-2026-09-10","requestedExpiresAt":"2026-09-10T14:00:00Z"}'
    ```
  • Codex CLI CONFIG_READY

    Add the rule to AGENTS.md at the repository root; Codex reads it at the start of every session and can run the curl in its sandbox.

    AGENTS.md
    # Agent Action Preflight (Jithox)
    
    Before any action that sends, publishes, buys, submits, accepts, tests or changes something outside the workspace:
    1. POST the planned action to https://jithox.com/api/agent-preflight/v1/evaluate (schema: https://jithox.com/api/agent-preflight/v1/schema).
    2. Act only on ALLOWED_TO_PREPARE. On HUMAN_APPROVAL_REQUIRED, show the owner the actionHash and stop. On BLOCKED or UNAVAILABLE, stop and report the reason codes.
    3. Never execute the external step yourself; Jithox does not execute either. Hand an approved hash to the official connector.
    4. Never put a credential, key or personal detail in the request; the endpoint refuses them.
    
    ```bash
    curl -s https://jithox.com/api/agent-preflight/v1/evaluate \
      -H 'content-type: application/json' \
      -d '{"schemaVersion":"jithox.agent-action-preflight-request/v1","action":{"type":"send_message","target":{"kind":"email","id":"customer:EXAMPLE-1"},"summary":"Reply to the customer's question."},"agent":{"id":"my-agent","client":"claude"},"owner":{"ref":"owner:me"},"requestedPermissions":["read","draft_messages","send_external_messages"],"dataClassification":"internal","money":null,"externalSideEffect":true,"reversible":"no","authority":{"kind":"none"},"humanApproval":null,"idempotencyKey":"reply-customer-1-2026-09-10","requestedExpiresAt":"2026-09-10T14:00:00Z"}'
    ```
  • Gemini CLI CONFIG_READY

    Add the rule to GEMINI.md in the project; Gemini CLI loads it as context and can execute the curl with its shell tool.

    GEMINI.md
    # Jithox Agent Action Preflight
    
    Before any action that sends, publishes, buys, submits, accepts, tests or changes something outside the workspace:
    1. POST the planned action to https://jithox.com/api/agent-preflight/v1/evaluate (schema: https://jithox.com/api/agent-preflight/v1/schema).
    2. Act only on ALLOWED_TO_PREPARE. On HUMAN_APPROVAL_REQUIRED, show the owner the actionHash and stop. On BLOCKED or UNAVAILABLE, stop and report the reason codes.
    3. Never execute the external step yourself; Jithox does not execute either. Hand an approved hash to the official connector.
    4. Never put a credential, key or personal detail in the request; the endpoint refuses them.
    
    ```bash
    curl -s https://jithox.com/api/agent-preflight/v1/evaluate \
      -H 'content-type: application/json' \
      -d '{"schemaVersion":"jithox.agent-action-preflight-request/v1","action":{"type":"send_message","target":{"kind":"email","id":"customer:EXAMPLE-1"},"summary":"Reply to the customer's question."},"agent":{"id":"my-agent","client":"claude"},"owner":{"ref":"owner:me"},"requestedPermissions":["read","draft_messages","send_external_messages"],"dataClassification":"internal","money":null,"externalSideEffect":true,"reversible":"no","authority":{"kind":"none"},"humanApproval":null,"idempotencyKey":"reply-customer-1-2026-09-10","requestedExpiresAt":"2026-09-10T14:00:00Z"}'
    ```
  • Cursor / Grok CONFIG_READY

    Save the rule as a Cursor rule file so every agent session in the project applies it; a Grok-based client that reads project rules uses the same file.

    .cursor/rules/jithox-agent-preflight.mdc
    ---
    description: Check every external action with Jithox Agent Action Preflight before acting
    alwaysApply: true
    ---
    
    Before any action that sends, publishes, buys, submits, accepts, tests or changes something outside the workspace:
    1. POST the planned action to https://jithox.com/api/agent-preflight/v1/evaluate (schema: https://jithox.com/api/agent-preflight/v1/schema).
    2. Act only on ALLOWED_TO_PREPARE. On HUMAN_APPROVAL_REQUIRED, show the owner the actionHash and stop. On BLOCKED or UNAVAILABLE, stop and report the reason codes.
    3. Never execute the external step yourself; Jithox does not execute either. Hand an approved hash to the official connector.
    4. Never put a credential, key or personal detail in the request; the endpoint refuses them.
    
    ```bash
    curl -s https://jithox.com/api/agent-preflight/v1/evaluate \
      -H 'content-type: application/json' \
      -d '{"schemaVersion":"jithox.agent-action-preflight-request/v1","action":{"type":"send_message","target":{"kind":"email","id":"customer:EXAMPLE-1"},"summary":"Reply to the customer's question."},"agent":{"id":"my-agent","client":"claude"},"owner":{"ref":"owner:me"},"requestedPermissions":["read","draft_messages","send_external_messages"],"dataClassification":"internal","money":null,"externalSideEffect":true,"reversible":"no","authority":{"kind":"none"},"humanApproval":null,"idempotencyKey":"reply-customer-1-2026-09-10","requestedExpiresAt":"2026-09-10T14:00:00Z"}'
    ```
  • Any HTTP or CLI agent CONFIG_READY

    One JSON request, one JSON answer. No key in this build; the response is no-store and carries the decision, the reason codes and the hash-bound receipt.

    curl
    curl -s https://jithox.com/api/agent-preflight/v1/evaluate \
      -H 'content-type: application/json' \
      -d '{"schemaVersion":"jithox.agent-action-preflight-request/v1","action":{"type":"send_message","target":{"kind":"email","id":"customer:EXAMPLE-1"},"summary":"Reply to the customer's question."},"agent":{"id":"my-agent","client":"claude"},"owner":{"ref":"owner:me"},"requestedPermissions":["read","draft_messages","send_external_messages"],"dataClassification":"internal","money":null,"externalSideEffect":true,"reversible":"no","authority":{"kind":"none"},"humanApproval":null,"idempotencyKey":"reply-customer-1-2026-09-10","requestedExpiresAt":"2026-09-10T14:00:00Z"}'
  • MCP tool (future MCP host) MCP_HOST_PENDING

    The MCP fleet lives in another repository owned by another team. The exact tool contract (name, input schema, output schema, decisions) is published in this build's schema document and in the Astra handoff under docs/handoffs, so the fleet can add the tool without inventing anything.

    Geen enkele MCP-server host deze tool vandaag. Het contract is een gesloten handoff naar de fleet.

    MCP tool contract
    {
      "name": "evaluate_action_preflight",
      "inputSchema": "https://jithox.com/api/agent-preflight/v1/schema#/request",
      "outputSchema": "https://jithox.com/api/agent-preflight/v1/schema#/result",
      "decisions": [
        "ALLOWED_TO_PREPARE",
        "HUMAN_APPROVAL_REQUIRED",
        "BLOCKED",
        "UNAVAILABLE"
      ],
      "executes": false
    }

Developer hub · Open Team Builder (Labs)