Built in connectors
Each is registered only when its configuration is present (packages/api/src/bootstrap/createConnectorRegistry.ts).
A capability whose connector is not configured is refused with
503 CONNECTOR_NOT_REGISTERED, before anything is
sent. Ask the server which policy and version govern a capability with GET /policies/in-effect?capability=....
Adding another built in connector is a change to Parmana’s code in several packages (the connector, the gateway
adapter, the catalog, credentials, signal verification, the policy binding). For a system of your own, use an external
connector instead.
External connectors
You run a small HTTPS endpoint in front of your system. Parmana releases every approved request for one capability to it as a signed release. The endpoint verifies the release with an SDK helper, acts with its own credentials, and answers. No shared secret is involved: the signature is the authentication.What the endpoint receives
parameters holds only the names the registration allows. The release expires 60 seconds after it is issued.
What the endpoint does
The SDK helper does the checks; your code does the action.signature.keyId, that audience is this endpoint, and that the release has not expired (with 30 seconds of clock
skew). The complete, runnable endpoints are typescript/examples/07-external-connector-endpoint.ts and
python/examples/13_external_connector_endpoint.py; replace their act function with the call into your system.
Then the endpoint:
- Acts only on
capability,targetandparametersfrom the verified release. - Records its answer by
businessTransactionIdin durable storage. Parmana may send the same release again after a timeout; the endpoint answers with its first result and does not act twice. - Answers
200with{ businessTransactionId, capability, success, result, executedAt }, echoing the first two from the release.resultis an object of at most 16 KB.
Register it: two people, no deploy
From then on the agent integrates exactly as in Chapter 3; nothing differs for an
external connector. The literal procedure, with what to expect and what to do at each step, is
Connect any external system.
Rules Parmana enforces
When it goes wrong
Status
Registration through maker checker is live in production. Releasing to a registered endpoint is built and tested, and not yet checked against a live endpoint in production.verifyParmanaRelease and verify_parmana_release are in the
repository and not yet published. What the endpoint answers is its claim, not proof that it acted
(docs/VERIFICATION-GAPS.md G-82).
See it run
Tutorial 123 (Chapter 2) registers an ERP endpoint through maker checker, releases to the TypeScript example endpoint, answers a retry once, refuses a release made for another endpoint, and stops at a revoke. The design and its security reasoning are indocs/adr/ADR-0013-Generic-External-Connector.md.