The full upstream README, mirrored here for reference. Install config, tool schemas, adoption signals, and an original overview live on the Quesen listing page.
Quesen is the deterministic decision-and-receipt core for agent actions — a typed security context in, a
PASS / REVIEW / BLOCK / SKIPverdict out, with machine reason codes and a receipt you can re-run byte-for-byte and prove. No model inference is in the scoring path, so the same input always yields the same verdict. It is built to sit behind injection detection, on top of agent identity, and to bill per decision (ASP/402).Unlike log-based governance layers whose audit trail is their word, kept by them, a Quesen receipt is independently verifiable by the caller — recomputable, and (engine signing enabled) Ed25519-signed. See
docs/architecture-gap-closers.mdand client-side enforcement + receipt verification inquesen-sdk≥ 0.5.0.This repository is the public developer portal. It contains only documentation, integration guides, examples, registry manifests, and reference links. No engine source code lives here. Quesen's engine implementation is sovereign, non-public infrastructure.
Live production
| Surface | URL |
|---|---|
| REST API | https://web-production-3df26.up.railway.app |
| MCP (Streamable HTTP) | https://web-production-3df26.up.railway.app/mcp |
| OpenAPI 3.1 | https://web-production-3df26.up.railway.app/openapi.json |
| Swagger UI | https://web-production-3df26.up.railway.app/docs |
| Health | https://web-production-3df26.up.railway.app/health |
| Version | https://web-production-3df26.up.railway.app/version |
Fastest path — no install, no signup, no card. Self-serve a free sandbox key and run a
real deterministic decision against production. Full guide: docs/QUICKSTART.md
· try it in the browser at senueren.co.za/try.
Published. The SDKs are live on PyPI and npm (
quesen-sdk0.5.0/ npm0.5.0;quesen-langchain,quesen-crewai,quesen-autogen0.3.0). Thebase_url+X-API-Key(including the sandbox key above) are identical across all SDKs.
| Framework | Package | Repository |
|---|---|---|
| LangChain / LangGraph | quesen-langchain | Shxnque/quesen-langchain |
| CrewAI | quesen-crewai | Shxnque/quesen-crewai |
| AutoGen v0.4+ | quesen-autogen | Shxnque/quesen-autogen |
| Python (core) | quesen-sdk | Shxnque/quesen-sdk-py |
| JavaScript / TypeScript | quesen-sdk (npm) | Shxnque/quesen-sdk-js |
Quesen exposes five MCP tools over the production endpoint. See
docs/mcp.md for the client-config snippet.
Autonomous agents make more decisions per second than any human oversight can audit. When those decisions involve capital — launching a token, opening a position, executing a trade, greenlighting a smart-contract deployment — the marginal cost of a bad decision is fatal.
Quesen answers exactly one question:
Should the calling agent proceed with this action?
Inputs are typed. Outputs are one of PROCEED, REVIEW, SKIP, always with a
risk_score in [0.0, 1.0], a confidence in [0.0, 1.0], and the exact
conflict rules that fired. Same inputs → same output. Every time. Every
response embeds engine_version, weights, and thresholds. Fully
reproducible. Fully auditable.
Published receipts are independently reproducible from this repo alone — no hosted service or private engine required:
All six UCP #724 vectors show a byte-for-byte three-way match between the
published fixture, the public reference, and the live engine
(verify/README.md, verify/three_way_match.json).
That doc also states honestly where independent verification stops today (the
production ruleset commit_sha is not publicly resolvable; receipts are not yet
cryptographically issuer-signed).
The egress/authority decision subset — the part security integrators gate on — is now independently verdict-replayable offline too, with zero network:
Six cases (OWASP-agentic + LoopX prepared-Effect PASS/REVIEW/BLOCK) recompute
byte-for-byte from the public reference evaluator, plus a prod-1→prod-2
integrity-flip check — no signup, key, or hosted call
(evaluation/conformance/README.md).
https://web-production-3df26.up.railway.appGET /health returns {"status":"ok","engine_version":"1.10.0"}GET /version returns full engine + billing + on-chain flags (ASP/1.0)Quesen is discoverable via Model Context Protocol registries and the standard
agent-directory ecosystem. See docs/registries.md for
the current state of each submission. Manifests:
smithery.yaml — Smithery.ai (canonical)mcp.json — MCP.so / generic MCP client (canonical).well-known/ai-plugin.json — OpenAI plugin
manifest / .well-known/ai-plugin.json autodiscoveryllms.txt — machine-readable summary for LLM crawlersThis is a documentation-only repository. Engine PRs cannot be accepted here.
If you have integration-specific feedback, please open an issue or read CONTRIBUTING.md.
SDK contributions belong in the corresponding public SDK repository:
Security issues: please read SECURITY.md before filing publicly.
Follow build updates, agent-governance notes, and Quesen releases on X: @SenuerenGroup · web: senueren.co.za · senueren.co.za/quesen.
If a Quesen integration or a merged contribution helped your project, a follow or a note at @SenuerenGroup is always appreciated.
MIT. See LICENSE.