Abe (Python) — pip install abe-ai
Abe is one control point before an AI agent acts.
It checks a proposed action against your policy and returns ACT, BLOCK or ESCALATE, plus an immutable,
hash-verified Judgment-Grounded Record of why. It runs entirely on your machine: no account, no API key, no
network, no model. Median evaluation time is well under a millisecond.
pip install abe-ai # or: npm install abe-ai
abe init # writes abe-policy.yaml + request.json
abe check request.json
Decision: ESCALATE
Reason: FINANCIAL_THRESHOLD_EXCEEDED
Rules: purchase_review_limit
Risk: MEDIUM
Record: jgr_01M3Q4...
Python
from abe import Abe
abe = Abe("abe-policy.yaml")
result = abe.check(
action={"type": "wire_transfer", "amount": 50000},
context={"agent_id": "finance-agent"},
)
if result.decision == "ACT":
... # execute exactly as evaluated
elif result.decision == "BLOCK":
... # do not execute; tell the user result.reason_code
else: # ESCALATE
... # hold; ask a human, or let a resolver decide
result.record.to_dict() # the Judgment-Grounded Record (store it, ship it to your SIEM)
TypeScript
import { Abe } from "abe-ai";
const abe = new Abe({ policy: "./abe-policy.yaml" });
const result = await abe.check({
action: { type: "purchase", amount: 12500, currency: "USD" },
context: { agent_id: "procurement-agent", principal_id: "user_123" },
});
console.log(result.decision); // "ESCALATE"
A policy
version: "0.1"
defaults: { unmatched: ESCALATE } # nothing matched -> needs judgment (fail closed)
rules:
- id: purchase_hard_limit
when: { all: [ { field: action.type, op: eq, value: purchase }, { field: action.amount, op: gt, value: 100000 } ] }
decision: BLOCK
reason_code: HARD_POLICY_VIOLATION
- id: purchase_review_limit
when: { all: [ { field: action.type, op: eq, value: purchase }, { field: action.amount, op: gt, value: 10000 } ] }
decision: ESCALATE
reason_code: FINANCIAL_THRESHOLD_EXCEEDED
- id: routine_purchase
when: { all: [ { field: action.type, op: eq, value: purchase }, { field: action.amount, op: lte, value: 500 } ] }
decision: ACT
judgment_required:
- action.type: terminate_employee
Also: authorization per agent, required evidence, risk and irreversibility thresholds, confidence minimums.
BLOCK beats ESCALATE beats ACT. Bad input or a broken rule returns ESCALATE / EVALUATION_FAILURE, never ACT.
Full reference: SPEC.md.
Every way to run it
| Library | pip install abe-ai · npm install abe-ai |
| CLI | abe check · validate-policy · validate-record · conformance · keygen |
| Local HTTP sidecar | abe serve --policy abe-policy.yaml → POST http://127.0.0.1:8787/v1/check (any language) |
| Docker sidecar | docker run -e ABE_TOKEN=… -v $PWD:/policy:ro -p 127.0.0.1:8787:8787 ghcr.io/flowinfosystems-index/abe |
| MCP server | pip install "abe-ai[mcp]" → abe mcp --policy /abs/abe-policy.yaml (tool: fjp_check_action) |
Records you can audit
Every call returns a record with the decision, every matched rule, the exact policy hash, the request hash,
and a SHA-256 record_hash (optionally Ed25519-signed with abe keygen). Records never change: outcomes and
resolutions are appended as linked records. Each one is a valid FJP-CONF v0.1 Judgment-Grounded Record.
abe check request.json --record-out jgr.json --sign-key abe-signing-key.pem
abe validate-record jgr.json --public-key abe-signing-key.pub.pem
When rules aren't enough: Flow
Abe is deliberately useful without Flow. When it returns ESCALATE, you can hand that one action to
Flow's judgment service and get a verb, a reason and a falsifiable record back:
from abe import Abe
from abe_flow import FlowResolver # pip install abe-flow
abe = Abe("abe-policy.yaml", resolver=FlowResolver(api_key=os.environ["FLOW_API_KEY"]))
ACT and BLOCK never leave your machine. Only escalations are sent (redacted), and if Flow is unreachable the
answer simply stays ESCALATE. Human-approval escalations are never auto-resolved.
Conformance
abe conformance --bench # FJP-CONF v0.1 Gate profile, Level 3 — 160 checks, offline
Repository
SPEC.md the normative specification
schemas/ JSON Schemas (request, response, record, policy)
python/ abe-ai (PyPI): core, CLI, HTTP, MCP, stores, signing, conformance
typescript/ abe-ai (npm): same API, same records, same hashes
flow-resolver/ abe-flow (PyPI): Gate → Flow for ESCALATE only
conformance/fixtures/ golden decisions + canonical-JSON vectors shared by every SDK
examples/ purchasing, software agent, physical agent, travel (+ Judd), Flow
Apache-2.0. FJP™, Abe™ (Abe) and FJP-CONF™ are trademarks of Flow Information Systems — see TRADEMARKS.md.
Extras
| Install | Adds |
|---|---|
pip install abe-ai |
core, CLI, HTTP server, stores (memory, file, SQLite), conformance — one dependency (PyYAML) |
pip install "abe-ai[signing]" |
Ed25519 record signing (abe keygen, --sign-key) |
pip install "abe-ai[mcp]" |
MCP server (abe mcp) |
abe.stores.contrib |
PostgresStore (psycopg 3), MongoStore (pymongo) — bring your own driver |
Metadata
Release files for abe-ai 0.2.0
For a detailed explanation of source distributions (sdists) and built distributions (wheels), please see the package formats documentation.
Source distribution (sdist)
| File | Size | Uploaded | |
|---|---|---|---|
| abe_ai-0.2.0.tar.gz | 67.7 kB | Details |
Built distribution (wheel)
| File | Interpreter | ABI | Platform | Reset |
|---|---|---|---|---|
| abe_ai-0.2.0-py3-none-any.whl | Python 3 | none | any | Details |
Total release size: 133.0 kB
Release files / abe_ai-0.2.0.tar.gz
| Download URL | abe_ai-0.2.0.tar.gz |
|---|---|
| Size | 67.7 kB |
| Tags | Source |
|
SHA-256 checksum How to use checksums |
1379612e653a3512a44283c2b10803f6f9852b61cf1cc47fc0e7f2f05302b78c
|
|
BLAKE2b-256 checksum How to use checksums |
fd4301beaf2326c67a851ec39c8a1d195218ca35aa1989d86baaadbb94b14e52
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency logRelease files / abe_ai-0.2.0-py3-none-any.whl
| Download URL | abe_ai-0.2.0-py3-none-any.whl |
|---|---|
| Size | 65.3 kB |
| Tags | Python 3 |
|
SHA-256 checksum How to use checksums |
e8b26ddd5c2e5e5fbc287c6578d844a2f26ce9180bc2679763199d235b9315fa
|
|
BLAKE2b-256 checksum How to use checksums |
577201fbd551fad748678f34f3f25d0e3d0b4b218d180a4295b4de58ebb231bf
|
| Upload date | |
|
Uploaded using Trusted Publishing? What is trusted publishing? |
Yes |
| Uploaded via |
twine/7.0.0 CPython/3.13.14
|
Provenance
Provenance describes where a file came from. On PyPI, provenance is shared via attestations, which provide a verifiable record of the build or publishing details. View details, limitations and caveats.
PyPI Publish Attestation
PyPI verified that this artifact, at this checksum, originated from the publisher listed below.
Signed by GitHub Actions, verified by PyPI on Sep 30, 2026.
Transparency log