Proprietary software, evaluation only. You may read, build and run Parmana
to assess it; any other use needs a written agreement. The client and
connector SDKs are the exception: they are open source under the Apache
License 2.0. See License and evaluation. Evaluators and auditors
start at Evaluate Parmana and the Audit
guide.
AI agent reading this?
GET /api-manifest.json on any deployment is a
single machine-readable index of the OpenAPI spec, auth scheme, and both real
SDKs with their actual current package versions, no page-scraping required. To
call a live server right away, use the public sandbox at
https://parmana-sandbox.vercel.app with the demo key on the
Playground. The Quickstart then gets you a
working local server and a real, committed test credential (not a production
secret) to call it with in under 10 minutes.What Parmana is
Think of how a card network authorizes a purchase. Visa doesn’t stock the shelves or move the money itself. It decides, quickly and cryptographically, whether the transaction is allowed, then hands the merchant’s bank a signed authorization to act on. Parmana plays that role for automated business actions. An agent proposes an action. Parmana’s policy engine decides, deterministically, whether it’s allowed. If approved, Parmana issues a signed, single-use, time-bounded authorization. Your own systems, through a Connector, are what actually execute it. Parmana never touches your systems directly, the same way a card network never touches the goods on the shelf. No AI agent action is authorized without a signed human approval, reads included. A policy can only approve when a trusted person has signed an approval for that action on that resource, and the approval is checked, not taken on the agent’s word. See Human approval.The trust chain, at a glance
packages/api/src/server.ts) wires the Execution Gateway unconditionally: there is no
code path where a request skips it. See How Parmana thinks for what
each stage guarantees and why.
Status tags used throughout this site
[AVAILABLE]
Built and tested in this repo today. Cites the source file(s) and/or test(s)
that prove it.
[PARTIAL]
Exists, but incomplete. States exactly what works and what doesn’t.
[ROADMAP]
Designed, not yet built. Says so in the first sentence, never documented as
if it ships.
Where to go next
Quickstart
Install to first authorized execution in under 10 minutes, using the
in-memory server.
Self hosted
Run Parmana on your own infrastructure with one Docker Compose command.
Decisions, keys and records stay in your network.
How Parmana thinks
The concepts behind the diagram above: policy, authorization, the gateway,
trust records.
End-to-end: agent to Paytm
The same flow against a real connector and real infrastructure, start to
finish.
SDKs
TypeScript and Python, both published, both with a builder that removes the
most common integration mistake.
Explore the REST API
One spec, three views: this site’s per-route reference, a live Swagger UI to
try requests, and a read-only ReDoc page.