Event-sourced agent engine — CLI and Python bindings for auditable AI workflows
Project description
zymi-core
Event-sourced agent engine for auditable AI workflows in Rust, YAML, and Python.
zymi-core helps you build agent workflows you can inspect after the fact. Every run is recorded as an immutable event stream in SQLite, agent side effects are mediated through intentions and boundary contracts, and pipelines execute as DAGs with parallel steps when possible.
Highlights
- Auditable by default: every state change is persisted as an event with hash-chain verification.
- Safer side effects: agents emit intentions first; contracts and approvals decide what is allowed to execute.
- Practical workflows: define agents and DAG pipelines in YAML, then run them from a small CLI.
- Declarative custom tools: add HTTP (and soon shell/Python) tools in
tools/*.yml— no Rust code required. - Flexible integration points: use the Rust crate, Python bindings, or both — Python can drive pipelines directly via
Runtime.for_project(...).run_pipeline(...), no subprocess. - LLM-provider ready: OpenAI-compatible providers, Anthropic support, Python tools, and LangFuse event services.
- JSON Schemas for configs:
zymi schema project|agent|pipeline|tooloutputs draft-07 JSON Schema for IDE autocomplete and LLM-assisted config generation.
Installation
| If you want to... | Install with... |
|---|---|
| CLI + Python bindings | pip install zymi-core |
| Rust crate only | zymi-core = "0.1" |
pip install zymi-core gives you both the zymi CLI command and the zymi_core Python module.
Quick Start
# Install
pip install zymi-core
# Create a demo project
mkdir zymi-demo
cd zymi-demo
zymi init --example research
# Add your LLM provider config to project.yml, then run the pipeline
zymi run research -i topic="event sourcing"
# Inspect what happened
zymi events --limit 20
zymi verify
For example, this is enough to get started with OpenAI:
llm:
provider: openai
model: gpt-4o
api_key: ${env.OPENAI_API_KEY}
What this gives you:
project.ymlfor provider config, policies, contracts, and defaultsagents/for agent definitionspipelines/for DAG workflowstools/for declarative custom tools (optional).zymi/events.dbfor the append-only event logoutput/andmemory/directories in the research example
Common CLI commands
zymi init --name my-project
zymi init --example research
zymi run main -i task="Summarize the architecture"
zymi run research -i topic="Rust event sourcing"
# Long-running mode: react to PipelineRequested events from any process
zymi serve research
zymi events
zymi events --stream conversation-1
zymi events --stream conversation-1 --verbose
zymi events --kind tool_call_completed --json
zymi verify
zymi verify --stream conversation-1
# JSON Schema for configs (useful for IDE autocomplete / LLM generation)
zymi schema project
zymi schema --all
Project Layout
A zymi project is just a directory with YAML files:
my-project/
project.yml
agents/
default.yml
pipelines/
main.yml
tools/ # optional — declarative custom tools
slack_post.yml
.zymi/
events.db
The default scaffold created by zymi init is intentionally small:
# project.yml
name: my-project
version: "0.1"
defaults:
timeout_secs: 30
max_iterations: 10
policy:
enabled: true
allow: ["ls *", "cat *", "echo *"]
deny: ["rm -rf *"]
# agents/default.yml
name: default
description: "Default agent"
tools:
- web_search
- read_file
- write_memory
max_iterations: 10
# pipelines/main.yml
name: main
steps:
- id: process
agent: default
task: "${inputs.task}"
input:
type: text
output:
step: process
Declarative Custom Tools
Drop a YAML file into tools/ to give your agents new capabilities without writing code:
# tools/slack_post.yml
name: slack_post
description: "Post a message to a Slack channel"
parameters:
type: object
properties:
channel:
type: string
text:
type: string
required: [channel, text]
implementation:
kind: http
method: POST
url: "https://slack.com/api/chat.postMessage"
headers:
Authorization: "Bearer ${env.SLACK_TOKEN}"
Content-Type: "application/json"
body_template: '{"channel": "${args.channel}", "text": "${args.text}"}'
Then reference it in an agent:
# agents/notifier.yml
name: notifier
tools:
- web_search
- slack_post # ← the custom tool
${env.*} variables are resolved at parse time; ${args.*} are resolved at call time from the LLM's arguments. Name collisions with built-in tools are a hard error.
Python Bindings
The same pip install zymi-core that gives you the CLI also exposes a Runtime for running pipelines directly, plus the lower-level Event, EventBus, EventStore, Subscription, and ToolRegistry primitives for custom integrations.
Run a pipeline from Python
from zymi_core import Runtime
# Loads project.yml + agents/ + pipelines/ from the given directory and
# builds the same Runtime `zymi run` and `zymi serve` use. `approval` is
# either "terminal" (fail-closed prompt on stdin, matches `zymi run`) or
# "none" (intentions tagged RequiresHumanApproval resolve to a deny).
rt = Runtime.for_project(".", approval="terminal")
result = rt.run_pipeline("research", {"topic": "rust event sourcing"})
print(result.success, result.final_output)
for step in result.step_results:
print(step.step_id, step.iterations, step.success)
rt.bus() and rt.store() hand out Python wrappers over the runtime's
own Arcs, so any subscriber you attach there sees exactly the events
the handler publishes — there is no second bus over the same SQLite file.
Tool registry and event primitives
from zymi_core import ToolRegistry
registry = ToolRegistry()
@registry.tool
def search(query: str) -> str:
return f"Results for: {query}"
result = registry.call("search", '{"query":"rust async"}')
intention_json = registry.to_intention("search", '{"query":"rust async"}')
definitions = registry.definitions()
For lower-level event primitives the same package gives you the event store and bus directly:
from zymi_core import Event, EventBus, EventStore
store = EventStore("./events.db")
bus = EventBus(store)
subscription = bus.subscribe()
event = Event(
stream_id="conversation-1",
kind={"type": "UserMessageReceived", "data": {
"content": {"User": "Hello"},
"connector": "python",
}},
source="python",
)
bus.publish(event)
received = subscription.try_recv()
Multi-Process Integration (Django, Celery, scripts)
The Python wrapper for EventStore opens the same SQLite file the Rust
side uses. There is no second IPC channel — events written from one
process are visible to every other process that opens the same store, and
a long-running zymi serve picks them up via a polling tail watcher
(see ADR-0012).
The canonical pattern: a web app publishes a PipelineRequested event,
zymi serve runs the pipeline, and the result comes back as a
PipelineCompleted event with the same correlation_id.
Terminal A — long-running Rust service:
cd my-zymi-project
zymi serve research
Terminal B — any Python process (e.g. a Django view):
import uuid
from zymi_core import Event, EventBus, EventStore
store = EventStore(".zymi/events.db")
bus = EventBus(store)
correlation_id = str(uuid.uuid4())
sub = bus.subscribe_correlation(correlation_id)
event = Event(
stream_id=f"web-req-{correlation_id}",
kind={"type": "PipelineRequested", "data": {
"pipeline": "research",
"inputs": {"topic": "rust event sourcing"},
}},
source="django",
)
event.with_correlation(correlation_id)
bus.publish(event)
# Block until the serve process publishes PipelineCompleted with the
# same correlation_id (timeout in seconds).
result = sub.recv(timeout_secs=300)
print(result.kind) # {"type": "PipelineCompleted", "data": {...}}
Because the SQLite store is the single source of truth, you also get
free auditing: zymi events --stream web-req-... shows everything that
happened during the run, and zymi verify checks the hash chain.
Inside zymi serve the PipelineRequested → RunPipeline translation is
done by EventCommandRouter (see
ADR-0013). It is re-exported
from zymi_core::runtime, so if you are building your own scheduler or
bot adapter you can wire the same router against your own Runtime
without copy-pasting cli/serve.rs.
Rust Crate
Add the crate to your Cargo.toml:
[dependencies]
zymi-core = "0.1"
Example:
use std::sync::Arc;
use zymi_core::{open_store, Event, EventBus, EventKind, Message, StoreBackend};
let store = open_store(StoreBackend::Sqlite { path: "events.db".into() })?;
let bus = EventBus::new(store.clone());
let mut rx = bus.subscribe().await;
let event = Event::new(
"conversation-1".into(),
EventKind::UserMessageReceived {
content: Message::User("Hello".into()),
connector: "cli".into(),
},
"cli".into(),
);
bus.publish(event).await?;
let received = rx.recv().await.unwrap();
assert_eq!(received.kind_tag(), "user_message_received");
let verified_count = store.verify_chain("conversation-1").await?;
For cross-process delivery in your own binary, spawn a StoreTailWatcher
on the same store/bus — it polls for events written by other processes
and fans them out into local subscribers without re-persisting them:
use std::time::Duration;
use zymi_core::StoreTailWatcher;
let watcher = StoreTailWatcher::new(store.clone(), bus.clone())
.with_interval(Duration::from_millis(100))
.spawn();
// ... later, on shutdown:
watcher.stop().await;
How It Works
zymi-core is built around a small set of ideas:
- Every meaningful state change becomes an event. The SQLite event store is the source of truth.
- Agents express intentions, not side effects. Intentions are evaluated against boundary contracts before execution.
- Pipelines are DAGs. Independent steps can run in parallel, while dependencies remain explicit.
- Runs stay replayable. You can inspect events with
zymi events --stream <id>and verify hash-chain integrity withzymi verify. - Custom tools are declarative. HTTP tools live in
tools/*.ymland are dispatched at runtime — no Rust code, no rebuild.
Core intention types include ExecuteShellCommand, WriteFile, ReadFile, WebSearch, WebScrape, WriteMemory, SpawnSubAgent, and CallCustomTool.
Feature Flags (Rust crate)
The pip wheel ships with python and cli enabled. These flags are relevant when depending on the Rust crate directly.
| Feature | Description |
|---|---|
python |
PyO3 bindings for the _zymi_core Python extension module |
cli |
The zymi CLI binary |
runtime |
Async runtime and HTTP dependencies used by runtime integrations |
webhook |
HTTP approval handler built on Axum |
services |
Event-bus services such as LangFuse |
Development
cargo test
cargo test --features services,webhook
cargo clippy -- -D warnings
cargo clippy --features services -- -D warnings
maturin develop --features python,cli
License
MIT
Project details
Release history Release notifications | RSS feed
Download files
Download the file for your platform. If you're not sure which to choose, learn more about installing packages.
Source Distribution
Built Distributions
Filter files by name, interpreter, ABI, and platform.
If you're not sure about the file name format, learn more about wheel file names.
Copy a direct link to the current filters
File details
Details for the file zymi_core-0.1.5.tar.gz.
File metadata
- Download URL: zymi_core-0.1.5.tar.gz
- Upload date:
- Size: 157.7 kB
- Tags: Source
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
8d7f1ee6960343c4a8035a27afd67655824b2a81fb730f0300e13f4daccb3f09
|
|
| MD5 |
fc4245e677b93ce81c59a3d8a2e8bbaa
|
|
| BLAKE2b-256 |
7017418de6ccfbb7916b7f5b73a494c2c8abab7529413b6f28847579bcb3d02f
|
Provenance
The following attestation bundles were made for zymi_core-0.1.5.tar.gz:
Publisher:
release.yml on metravod/zymi-core
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
zymi_core-0.1.5.tar.gz -
Subject digest:
8d7f1ee6960343c4a8035a27afd67655824b2a81fb730f0300e13f4daccb3f09 - Sigstore transparency entry: 1280192060
- Sigstore integration time:
-
Permalink:
metravod/zymi-core@cb0a24da0dae0a4a070bf3f225ca5cf6a78c29f5 -
Branch / Tag:
refs/tags/v0.1.5 - Owner: https://github.com/metravod
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@cb0a24da0dae0a4a070bf3f225ca5cf6a78c29f5 -
Trigger Event:
push
-
Statement type:
File details
Details for the file zymi_core-0.1.5-cp311-cp311-win_amd64.whl.
File metadata
- Download URL: zymi_core-0.1.5-cp311-cp311-win_amd64.whl
- Upload date:
- Size: 4.2 MB
- Tags: CPython 3.11, Windows x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
da562f71196fcd4ed47238651fe1902a1341a611edc1a94ef1a0e0bfd4f2cc05
|
|
| MD5 |
df71bff7e91509010c78463d4aa5c229
|
|
| BLAKE2b-256 |
7dbda044dd2bfd3dcc2b8e920f6a3b93f89e4dc89055028fe1390cb97f061307
|
Provenance
The following attestation bundles were made for zymi_core-0.1.5-cp311-cp311-win_amd64.whl:
Publisher:
release.yml on metravod/zymi-core
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
zymi_core-0.1.5-cp311-cp311-win_amd64.whl -
Subject digest:
da562f71196fcd4ed47238651fe1902a1341a611edc1a94ef1a0e0bfd4f2cc05 - Sigstore transparency entry: 1280192073
- Sigstore integration time:
-
Permalink:
metravod/zymi-core@cb0a24da0dae0a4a070bf3f225ca5cf6a78c29f5 -
Branch / Tag:
refs/tags/v0.1.5 - Owner: https://github.com/metravod
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@cb0a24da0dae0a4a070bf3f225ca5cf6a78c29f5 -
Trigger Event:
push
-
Statement type:
File details
Details for the file zymi_core-0.1.5-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl.
File metadata
- Download URL: zymi_core-0.1.5-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl
- Upload date:
- Size: 4.1 MB
- Tags: CPython 3.11, manylinux: glibc 2.17+ x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
5e07959f97c7fe362ed45ceef243552c0c9946336eb275d67d3dc8ff0e727e05
|
|
| MD5 |
5cc969495bcaca1ed2b129a63ce09d41
|
|
| BLAKE2b-256 |
012536376c9c05f1ba994ea71dfb608a45669e85d011d260e3a20e0e2c61abab
|
Provenance
The following attestation bundles were made for zymi_core-0.1.5-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl:
Publisher:
release.yml on metravod/zymi-core
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
zymi_core-0.1.5-cp311-cp311-manylinux_2_17_x86_64.manylinux2014_x86_64.whl -
Subject digest:
5e07959f97c7fe362ed45ceef243552c0c9946336eb275d67d3dc8ff0e727e05 - Sigstore transparency entry: 1280192076
- Sigstore integration time:
-
Permalink:
metravod/zymi-core@cb0a24da0dae0a4a070bf3f225ca5cf6a78c29f5 -
Branch / Tag:
refs/tags/v0.1.5 - Owner: https://github.com/metravod
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@cb0a24da0dae0a4a070bf3f225ca5cf6a78c29f5 -
Trigger Event:
push
-
Statement type:
File details
Details for the file zymi_core-0.1.5-cp311-cp311-manylinux_2_17_aarch64.manylinux2014_aarch64.whl.
File metadata
- Download URL: zymi_core-0.1.5-cp311-cp311-manylinux_2_17_aarch64.manylinux2014_aarch64.whl
- Upload date:
- Size: 3.8 MB
- Tags: CPython 3.11, manylinux: glibc 2.17+ ARM64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
ff11736ed988d96239994070ce65a229f760e1a65e6e063ba36146cc8723048c
|
|
| MD5 |
e5a479f5e0151ab8f219e42443024e93
|
|
| BLAKE2b-256 |
6f977b98f5ad5b1e53c7be6bfa7e65171cf7598c80e8e75197c78166cd1d8314
|
Provenance
The following attestation bundles were made for zymi_core-0.1.5-cp311-cp311-manylinux_2_17_aarch64.manylinux2014_aarch64.whl:
Publisher:
release.yml on metravod/zymi-core
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
zymi_core-0.1.5-cp311-cp311-manylinux_2_17_aarch64.manylinux2014_aarch64.whl -
Subject digest:
ff11736ed988d96239994070ce65a229f760e1a65e6e063ba36146cc8723048c - Sigstore transparency entry: 1280192069
- Sigstore integration time:
-
Permalink:
metravod/zymi-core@cb0a24da0dae0a4a070bf3f225ca5cf6a78c29f5 -
Branch / Tag:
refs/tags/v0.1.5 - Owner: https://github.com/metravod
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@cb0a24da0dae0a4a070bf3f225ca5cf6a78c29f5 -
Trigger Event:
push
-
Statement type:
File details
Details for the file zymi_core-0.1.5-cp311-cp311-macosx_11_0_arm64.whl.
File metadata
- Download URL: zymi_core-0.1.5-cp311-cp311-macosx_11_0_arm64.whl
- Upload date:
- Size: 3.7 MB
- Tags: CPython 3.11, macOS 11.0+ ARM64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
035ee1d468fe95a3ca1523a30375b7c6a55468537b3121fb61973f4aa6e46525
|
|
| MD5 |
fbd010c058cae98204c4cb930b4706ed
|
|
| BLAKE2b-256 |
4a47942813b741d777d222210844ea617b641cf7aa93069ed10d3900309ef245
|
Provenance
The following attestation bundles were made for zymi_core-0.1.5-cp311-cp311-macosx_11_0_arm64.whl:
Publisher:
release.yml on metravod/zymi-core
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
zymi_core-0.1.5-cp311-cp311-macosx_11_0_arm64.whl -
Subject digest:
035ee1d468fe95a3ca1523a30375b7c6a55468537b3121fb61973f4aa6e46525 - Sigstore transparency entry: 1280192067
- Sigstore integration time:
-
Permalink:
metravod/zymi-core@cb0a24da0dae0a4a070bf3f225ca5cf6a78c29f5 -
Branch / Tag:
refs/tags/v0.1.5 - Owner: https://github.com/metravod
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@cb0a24da0dae0a4a070bf3f225ca5cf6a78c29f5 -
Trigger Event:
push
-
Statement type:
File details
Details for the file zymi_core-0.1.5-cp311-cp311-macosx_10_12_x86_64.whl.
File metadata
- Download URL: zymi_core-0.1.5-cp311-cp311-macosx_10_12_x86_64.whl
- Upload date:
- Size: 3.9 MB
- Tags: CPython 3.11, macOS 10.12+ x86-64
- Uploaded using Trusted Publishing? Yes
- Uploaded via: twine/6.1.0 CPython/3.13.12
File hashes
| Algorithm | Hash digest | |
|---|---|---|
| SHA256 |
f1e8c223b0f3fcfae0cb5f32d2fb79204f4781e67b410cdda931bf3f8f033754
|
|
| MD5 |
77894ac1d1b07785e36754bb4bde4c3e
|
|
| BLAKE2b-256 |
a8ef3b1226045227a28542e34a8578a3979aa37b17b9b95dabd1d85e31421033
|
Provenance
The following attestation bundles were made for zymi_core-0.1.5-cp311-cp311-macosx_10_12_x86_64.whl:
Publisher:
release.yml on metravod/zymi-core
-
Statement:
-
Statement type:
https://in-toto.io/Statement/v1 -
Predicate type:
https://docs.pypi.org/attestations/publish/v1 -
Subject name:
zymi_core-0.1.5-cp311-cp311-macosx_10_12_x86_64.whl -
Subject digest:
f1e8c223b0f3fcfae0cb5f32d2fb79204f4781e67b410cdda931bf3f8f033754 - Sigstore transparency entry: 1280192066
- Sigstore integration time:
-
Permalink:
metravod/zymi-core@cb0a24da0dae0a4a070bf3f225ca5cf6a78c29f5 -
Branch / Tag:
refs/tags/v0.1.5 - Owner: https://github.com/metravod
-
Access:
public
-
Token Issuer:
https://token.actions.githubusercontent.com -
Runner Environment:
github-hosted -
Publication workflow:
release.yml@cb0a24da0dae0a4a070bf3f225ca5cf6a78c29f5 -
Trigger Event:
push
-
Statement type: