2026-10-11 16:38 UTC

Kepil’s maintainer claims its released alpha combines agent identity, fail-closed mandate checks, tamper-evident journals, and human-controlled compensating actions, enabling auditable, bounded execution and partial rollback for workflows routed through its gateway.

state: watchingheat: lowuncertainty: mediumknownscott: lowagentic-security agent-identity audit-logs agent-harnessesoleg-vdvKepil

What is this?

Kepil (github.com/oleg-vdv/kepil) is a solo-maintainer, pip-installable alpha (AGPL-3.0, zero-dependency stdlib core) claiming an accountability layer for AI agents: per-agent-version 'passports', per-job machine-readable 'mandates' with spending limits and required human confirmations, a fail-closed action gateway checked before any model call, and a hash-chained append-only JSONL journal with an external verifier; undo walks operator-only compensating actions backwards through the journal and halts at the first non-undoable step. Its MCP server deliberately omits the confirmation tool so no AI client can approve an irreversible action — approvals route to a human via a localhost-bound panel or Telegram. Everything substantive in the supplied results is Kepil's own README self-description: no third-party audit, adoption, or independent coverage of Kepil appears, and the case's own numbers show near-zero traction. What the surrounding results do show is a crowding category — a 'Deterministic Agent Control Protocol' MCP governance gateway with tamper-evident ledgers and human approvals, Swirls marketing runtime-enforced tamper-evident agent logs with per-run identity, and 'bounded execution' now formalized as an NHI/IAM governance term — so Kepil's specific claims remain unvalidated even as its pattern enters mainstream vocabulary.

Why it matters to Scott

Kepil's claimed stack is a point-for-point restatement of positions Scott's own wikis already hold — ip:framework.agent-provenance-stack (identity/intent/artefact/execution chain: passports and mandates), ip:framework.decision-authority-infrastructure (fail-closed gate checked before the model call, ALLOW/PAUSE/DENY), ip:source.decision-attestation-packages (tamper-evident decision-time receipts), and ip:source.compliance-cosplay / ip:concept.manners-vs-physics (human confirmation structurally unreachable by MCP clients, enforced by test). With near-zero traction, no third-party validation of any security claim, and sibling radar episodes (Bulwark, AgentGate, Agent_acid) already tracking near-identical identity-plus-gateway-plus-journal claims, nothing new arrives on either side; the _qnt threshold-cryptography release is category-level corroboration of the accountability-gateway pattern, not validation of Kepil itself.
ip:framework.agent-provenance-stackip:framework.decision-authority-infrastructureip:source.decision-attestation-packagesip:source.compliance-cosplayip:concept.manners-vs-physicsradar:bulwark-agent-security-gatewayradar:agentgate-signed-agent-receiptsradar:agent-acid-rollback-guardrailsradar:concept.agent-governanceradar:concept.agent-identity
queries asked of Scott's wikis
  • agent provenance stack / decision authority infrastructure
  • fail-closed tool gateway before model call
  • tamper-evident hash-chained audit journal design
  • human confirmation unreachable by MCP client tool surface
  • compensating action rollback for agent workflows
  • agent identity passports and machine-readable mandates

Measured heat

now 0 pts/hpeak 0 pts/hcomments 0/hpeers p14momentum: steady2 platformsage 659h
points/hour across evidence · reading as of 2026-10-12 02:59:37.977291+11:00 · deterministic, not a model opinion

How the heat travelled

09-14 06:21 (minted)⭐ origin echo-reconstructedKepil presents an alpha accountability layer with passports, mandates, a fail-closed action gateway, hash-chained journals, and operator-onl
oleg-vdv on github (echo) · attributed from hn.story.49692366 · published time unknown
—
09-14 05:28first on hacker news · published · lag ?Show HN: Kepil – passport, mandate and tamper-evident journal for AI agents
ipgleg
—
09-14 05:28amplified on hacker news 👑hn.story.49692366
ipgleg
peak 2 · 0 comments · 65% of case engagement
09-25 12:07amplified on hacker newshn.story.49843480
_qnt
peak 1 · 0 comments · 35% of case engagement
09-14 06:20our radar first saw it · lag ?discovery anchor: hn.story.49692366—
pace: p32 vs 1032 stories at the 336h mark (now 659h old) — ahead of addom-local-coding-harness (1.5x), behind agentsec-static-config-auditing (0.8x)

Evidence (3) — ⭐ canonical anchor

sourceobjectauthorscorecomments
🟧 hnShow HN: Kepil – passport, mandate and tamper-evident journal for AI agents
Retrieved article excerpt

Open article · Retrieved 2026-09-14T06:21:36.233866+00:00

# Kepil

[PyPI](https://pypi.org/project/kepil/)
[License: AGPL v3](https://github.com/oleg-vdv/kepil/blob/main/LICENSE)

**Accountability layer for AI agents.** Give every agent a passport, put every
action through one gate, and keep a log that cannot be rewritten afterwards.

> 53% of organisations have had an AI agent exceed its intended permissions.
> 48% of agents in production run with no monitoring at all. Only 22% treat an
> agent as an entity with its own identity.
> — Cloud Security Alliance and State of AI Agent Security, 2026

Kepil is what the other 78% are missing: identity, mandate, enforcement,
evidence — and the part nobody else does, **undo**.

```
pip install kepil
python -m kepil.admin        # http://localhost:7317
```

Русская версия: [README.ru.md](https://github.com/oleg-vdv/kepil/blob/main/README.ru.md)

---

## What it does

**Passport.** Every agent version gets an immutable card: who built it, who runs
it, what it does, what it will *never* do, its risk class, its autonomy class,
its limits, and when its risks are due for review. A new version is a new card;
the old one is kept forever.

**Mandate.** A machine-readable power of attorney for one job: allowed actions,
allowed systems, spending limits, a validity window, and which action types must
be confirmed by a human. Anything not explicitly allowed is refused.

**Gate.** The single point through which an agent touches the outside world.
Every action is checked against the mandate *before* a model is even called.
Fail-closed: any error inside the check means refusal, never a pass.

**Journal.** Append-only JSONL where every record carries the hash of the one
before it. Editing or deleting a record is detectable — by anyone, using an
independent implementation:

```
npx proofbyte-agent-trace verify data/journal.jsonl
```

**Undo.** The journal is a graph of actions, and every profession declares its
compensating action. Kepil walks that graph backwards and stops honestly at the
first step that cannot be undone. Agent platforms record what happened; this one
puts it back.

**Confirmations on your phone.** Irreversible actions arrive in Telegram with
two buttons — approve or return — so being accountable does not mean sitting at
a laptop.

## Use it from any MCP client

Kepil ships an MCP server, so an editor, an assistant or another agent can work
through it — and every action still passes the same gate into the same journal.

```
{
  "mcpServers": {
    "kepil": { "command": "python", "args": ["-m", "kepil.mcp"] }
  }
}
```

Seven tools: list professions, create an order, run a step, read order status,
see what is waiting for a human, verify the journal, read an agent passport.

**One tool is deliberately missing: confirmation.** If a model could approve an
irreversible action, the human would drop out of the chain and the whole design
would be pointless. The confirmation card goes to a person — in the panel or in
Telegram — and no MCP client can press it. A test enforces this.

## Guard your existing automations

Kepil has a small JSON API, so an n8n workflow, a Make scenario or your own
script can ask permission before acting:

```
curl -X POST http://localhost:7317/api/check   -H "Authorization: Bearer $KEPIL_API_TOKEN"   -H "Content-Type: application/json"   -d '{"order_id":"ord-0042","action":"send:message","system":"whatsapp.local"}'
```

```
{ "decision": "await_human", "allowed": false, "needs_human": true,
  "reason": "необратимое действие: требуется подтверждение человека" }
```

The answer is recorded in the journal, so later you can show on what grounds the
automation did — or did not do — something. For n8n there is a ready node:
[n8n-nodes-kepil](https://github.com/oleg-vdv/n8n-nodes-kepil).

**The API stays off until you set a token** (panel → Settings, or
`KEPIL_API_TOKEN`). A panel bound to localhost is protected by the binding; a
programmatic interface is not, so it is disabled by default.

## An agent here is never fully autonomous

`AgentPassport` refuses to be constructed with the autonomy class where a human
can no longer cancel a decision. That is a deliberate architectural limit rather
than a missing feature — see
[ADR-0002](https://github.com/oleg-vdv/kepil/blob/main/docs/decisions/ADR-0002-medium-autonomy.md). The gate enforces the
same rule regardless of what a profession definition claims.

## Professions: behaviour as data, not code

An agent's job is a JSON description: ordered steps, boundaries, limits,
irreversible action patterns, rollback rules. Adding a new kind of work means
adding a file — or filling in a form in the panel. The dangerous parts stay in
code and under test.

Five ship with the project: inbound leads, process automation, bookkeeping
documents, AI-adoption audit, public-procurement packages.

## Undo that stops honestly

An order's journal is a sequence of actions and every profession declares the
compensating action for each, so the panel can walk it backwards: pick a window,
and the pass runs from the last action towards earlier ones, stopping at the
first one that cannot be undone. What will happen is shown **before** the button
is pressed, naming the step where the pass will stop — an undo promise that
quietly fails is worse than no undo at all. The result is recorded as an
operator's decision, which is why neither the MCP server nor the JSON API can
roll anything back: an agent undoing its own actions would be signing in
somebody else's name.

## The panel

`python -m kepil.admin` opens an operator console: orders, professions, agent
passports, a meter (actions, tokens, cost, human time replaced), the compliance
generator, the journal with chain verification and anchoring, and settings.

State is plain JSON files under `KEPIL_DATA` (default `./data`). No database:
you can open them, read them, and attach them to a dispute.

## Compliance packs

Documentation requirements differ by country and change faster than code, so the
texts live outside the engine. The neutral pack shipped here follows
international practice (ISO/IEC 42001, record-keeping in the spirit of the EU AI
Act). Jurisdiction packs — for example Kazakhstan's AI Law No. 230-VIII with
order No. 95/НҚ — are dropped into `$KEPIL_DATA/packs` as files.

## Design rules

- **Zero dependencies.** The core runs on the Python 3.11+ standard library, and
  CI fails the build if a third-party import appears. That keeps Kepil
  installable inside an air-gapped perimeter, and keeps the supply-chain attack
  surface of a tool that sees every action at zero.
- **Values never enter the journal** — only types, counts and hashes.
- **The verifier is a separate implementation in another language.** Proof that
  only its own author can check is not proof.

## Related projects

| Project | Role |
| --- | --- |
| [agent-trace](https://github.com/oleg-vdv/agent-trace) | Independent journal verification and evidence packs (MIT) |
| [AI-Gateway](https://github.com/oleg-vdv/AI-Gateway) | PII and secret masking between your apps and external models |
| [AutoGov](https://github.com/oleg-vdv/AutoGov) | Discovery of shadow automations and the credentials they can reach |

## Status

Alpha, 115 tests. Interfaces may still change. Nothing here is a legal opinion:
before relying on generated documents, have them reviewed by a lawyer in your
jurisdiction.

## License

AGPL-3.0-or-later. Running a network service built on Kepil obliges you to
release your own source under the same terms — or to take a commercial licence.
See [NOTICE.md](https://github.com/oleg-vdv/kepil/blob/main/NOTICE.md).
ipgleg20
🟧 echo.github ⭐Kepil presents an alpha accountability layer with passports, mandates, a fail-closed action gateway, hash-chained journals, and operator-onloleg-vdv——
🟧 hnShow HN: Threshold Cryptography for AI Agents Using Payments and Digital Assets_qnt10

Interpretation history

Decision trace