Skip to main content
Parmana sits between an AI agent (or a script, or a person) and the systems that carry out its actions. Before anything executes, Parmana checks it against a policy you write and issues a signed, single-use authorization. After it executes, you have an independently verifiable signed record of exactly what happened. The Quickstart runs a local server step by step.
Proprietary software, evaluation only. You may read, build and run Parmana to assess it; any other use needs a written agreement. The client and connector SDKs are the exception: they are open source under the Apache License 2.0. See License and evaluation. Evaluators and auditors start at Evaluate Parmana and the Audit guide.
Try it now, with nothing to install. The Playground is a live Parmana sandbox with a published demo key: send a request, watch the policy refuse it, get a signed approval, send it again, and verify the signed record yourself. Every Try it panel in the REST API tab calls the sandbox with the demo key filled in.
AI agent reading this? GET /api-manifest.json on any deployment is a single machine-readable index of the OpenAPI spec, auth scheme, and both real SDKs with their actual current package versions, no page-scraping required. To call a live server right away, use the public sandbox at https://parmana-sandbox.vercel.app with the demo key on the Playground. The Quickstart then gets you a working local server and a real, committed test credential (not a production secret) to call it with in under 10 minutes.

What Parmana is

Think of how a card network authorizes a purchase. Visa doesn’t stock the shelves or move the money itself. It decides, quickly and cryptographically, whether the transaction is allowed, then hands the merchant’s bank a signed authorization to act on. Parmana plays that role for automated business actions. An agent proposes an action. Parmana’s policy engine decides, deterministically, whether it’s allowed. If approved, Parmana issues a signed, single-use, time-bounded authorization. Your own systems, through a Connector, are what actually execute it. Parmana never touches your systems directly, the same way a card network never touches the goods on the shelf. No AI agent action is authorized without a signed human approval, reads included. A policy can only approve when a trusted person has signed an approval for that action on that resource, and the approval is checked, not taken on the agent’s word. See Human approval.

The trust chain, at a glance

Every stage in that chain is real, tested code, not a diagram of intent. The default local server (packages/api/src/server.ts) wires the Execution Gateway unconditionally: there is no code path where a request skips it. See How Parmana thinks for what each stage guarantees and why.

Status tags used throughout this site

[AVAILABLE]

Built and tested in this repo today. Cites the source file(s) and/or test(s) that prove it.

[PARTIAL]

Exists, but incomplete. States exactly what works and what doesn’t.

[ROADMAP]

Designed, not yet built. Says so in the first sentence, never documented as if it ships.
A page or section with no tag is a bug in this site, file it as such.

Where to go next

Quickstart

Install to first authorized execution in under 10 minutes, using the in-memory server.

Self hosted

Run Parmana on your own infrastructure with one Docker Compose command. Decisions, keys and records stay in your network.

How Parmana thinks

The concepts behind the diagram above: policy, authorization, the gateway, trust records.

End-to-end: agent to Paytm

The same flow against a real connector and real infrastructure, start to finish.

SDKs

TypeScript and Python, both published, both with a builder that removes the most common integration mistake.

Explore the REST API

One spec, three views: this site’s per-route reference, a live Swagger UI to try requests, and a read-only ReDoc page.
Content on this site is periodically verified against a specific commit; see Changelog for what changed and when.