Quesen β Developer Portal

Quesen is the deterministic decision-and-receipt core for agent actions β
a typed security context in, a PASS / REVIEW / BLOCK / SKIP verdict out, with
machine reason codes and a receipt you can re-run byte-for-byte and prove.
No model inference is in the scoring path, so the same input always yields the
same verdict. It is built to sit behind injection detection, on top of
agent identity, and to bill per decision (ASP/402).
Unlike log-based governance layers whose audit trail is their word, kept by
them, a Quesen receipt is independently verifiable by the caller β
recomputable, and (engine signing enabled) Ed25519-signed. See
docs/architecture-gap-closers.md and
client-side enforcement + receipt verification in quesen-sdk β₯ 0.5.0.
Production engine signing is live β verify a real signed receipt yourself in
docs/verify-live-receipt.md (no trust in Senueren required).
This repository is the public developer portal. It contains only
documentation, integration guides, examples, registry manifests, and
reference links. No engine source code lives here. Quesen's engine
implementation is sovereign, non-public infrastructure.
Live production
| Surface | URL |
|---|
| REST API | https://web-production-3df26.up.railway.app |
| MCP (Streamable HTTP) | https://web-production-3df26.up.railway.app/mcp |
| OpenAPI 3.1 | https://web-production-3df26.up.railway.app/openapi.json |
| Swagger UI | https://web-production-3df26.up.railway.app/docs |
| Health | https://web-production-3df26.up.railway.app/health |
| Version | https://web-production-3df26.up.railway.app/version |
Quick start (30 seconds)
Fastest path β no install, no signup, no card. Self-serve a free sandbox key and run a
real deterministic decision against production. Full guide: docs/QUICKSTART.md
Β· try it in the browser at senueren.co.za/try.
curl -X POST https://web-production-3df26.up.railway.app/sandbox/keys
curl -X POST https://web-production-3df26.up.railway.app/validate \
-H "X-API-Key: sk_sandbox_..." \
-H "Content-Type: application/json" \
-d '{"domain_age_days": 1, "engagement_ratio": 0.95, "scam_keyword_count": 4}'
SDKs
Published. The SDKs are live on PyPI and npm (quesen-sdk 0.5.0 / npm 0.5.0;
quesen-langchain, quesen-crewai, quesen-autogen 0.3.0). The
base_url + X-API-Key (including the sandbox key above) are identical across all SDKs.
Python
from quesen_sdk import QuesenClient
q = QuesenClient(base_url="https://web-production-3df26.up.railway.app",
api_key="YOUR_KEY")
verdict = q.validate(domain_age_days=1, engagement_ratio=0.95, scam_keyword_count=4)
if verdict.decision == "SKIP":
return
JavaScript / TypeScript
import { QuesenClient } from "quesen-sdk";
const q = new QuesenClient({
baseUrl: "https://web-production-3df26.up.railway.app",
apiKey: process.env.QUESEN_API_KEY,
});
const verdict = await q.validate({
domain_age_days: 1,
engagement_ratio: 0.95,
scam_keyword_count: 4,
});
Framework wrappers
MCP (Claude Desktop, Cursor, Windsurf, etc.)
Quesen exposes five MCP tools over the production endpoint. See
docs/mcp.md for the client-config snippet.
Why Quesen?
Autonomous agents make more decisions per second than any human oversight can
audit. When those decisions involve capital β launching a token, opening a
position, executing a trade, greenlighting a smart-contract deployment β the
marginal cost of a bad decision is fatal.
Quesen answers exactly one question:
Should the calling agent proceed with this action?
Inputs are typed. Outputs are one of PROCEED, REVIEW, SKIP, always with a
risk_score in [0.0, 1.0], a confidence in [0.0, 1.0], and the exact
conflict rules that fired. Same inputs β same output. Every time. Every
response embeds engine_version, weights, and thresholds. Fully
reproducible. Fully auditable.
What Quesen is not
- Not an LLM wrapper. No prompts. No probabilities.
- Not a chatbot. It is A2A infrastructure.
- Not a KYC/identity system. It scores risk, not identity.
- Not chain-locked / framework-locked / LLM-locked. Ecosystem-neutral by design.
Documentation
Independent verification
Published receipts are independently reproducible from this repo alone β no
hosted service or private engine required:
python3 verify/verify_receipts.py
python3 verify/verify_receipts.py --live
All six UCP #724 vectors show a byte-for-byte three-way match between the
published fixture, the public reference, and the live engine
(verify/README.md, verify/three_way_match.json).
That doc also states honestly where independent verification stops today (the
production ruleset commit_sha is not publicly resolvable; receipts are not yet
cryptographically issuer-signed).
The egress/authority decision subset β the part security integrators gate on β
is now independently verdict-replayable offline too, with zero network:
python3 evaluation/conformance/verify_conformance.py
Six cases (OWASP-agentic + LoopX prepared-Effect PASS/REVIEW/BLOCK) recompute
byte-for-byte from the public reference evaluator, plus a prod-1βprod-2
integrity-flip check β no signup, key, or hosted call
(evaluation/conformance/README.md).
Tutorials
Live status
- Production:
https://web-production-3df26.up.railway.app
- Health check:
GET /health returns {"status":"ok","engine_version":"1.10.0"}
- Version snapshot:
GET /version returns full engine + billing + on-chain flags (ASP/1.0)
- Uptime and version widget on senueren.co.za/quesen
Registry presence
Quesen is discoverable via Model Context Protocol registries and the standard
agent-directory ecosystem. See docs/registries.md for
the current state of each submission. Manifests:
Contributing
This is a documentation-only repository. Engine PRs cannot be accepted here.
If you have integration-specific feedback, please open an issue or read CONTRIBUTING.md.
SDK contributions belong in the corresponding public SDK repository:
Security issues: please read SECURITY.md before filing publicly.
Follow build updates, agent-governance notes, and Quesen releases on X:
@SenuerenGroup Β· web: senueren.co.za Β· senueren.co.za/quesen.
If a Quesen integration or a merged contribution helped your project, a follow or a note at @SenuerenGroup is always appreciated.
License
MIT. See LICENSE.