Skip to main content
VhyxSeal
Get started
Live Try to fool an agent in the security lab

Tell AI agents what your UI does — and when to ask a human.

AI agents now use websites for people — but they only see pixels. VhyxSeal gives every component a machine-readable contract and publishes them as one signed manifest agents can trust.

npm install @vhyxseal/react @vhyxseal/core
GET /__agent__/manifest.json200 · signed
{
  "domain": "shop.example",
  "components": 18,
  "capabilities": ["purchase-item", "manage-account"],
  "signature": "hmac-sha256:9f2c…41ab"
}
Signature validDomain boundInjection-clean
  1. › read search-productslow · allowed
  2. › read place-orderhigh · asks a person
  3. › read delete-accountcritical · asks a person
8security layers
9packages
4frameworks: React, Vue, vanilla, Next.js
0runtime dependencies in core
The problem

Agents are guessing

A web page was built for eyes. An agent reading it has to infer everything that matters.

What does it do?

A button labelled “Continue” could save a draft or charge a card.

How risky is it?

Nothing in the markup says an action is destructive or irreversible.

Who must approve?

There is no standard way to say “a person has to confirm this”.

One component, two audiences

OpenAPI for your UI

Nothing changes for people. Agents get a precise, typed contract they can trust.

What a person sees

To a person, these are three buttons. Choose one to see what an AI agent reads for it.

What an agent readshighhuman confirms
{
  "id": "place-order",
  "intent": "place-order",
  "safetyLevel": "high",
  "requiresConfirmation": true,
  "destructive": false,
  "reversible": true,
  "consequence": "Creates an order and charges the saved card"
}

Generated live by defineContract() from @vhyxseal/core.

The manifest

How an agent uses your site

Your site publishes every contract as a signed manifest at /__agent__/manifest.json. The agent verifies the signature, acts freely on low-risk actions, and stops to ask a person before anything that needs confirmation. Each action carries a single-use token.

This page publishes its own manifest — try /__agent__/manifest.json. Diagram by VhyxChart.

Security

Security is the foundation, not a feature

VhyxSeal sits between agents and your site, so every layer assumes the one above it can fail.

Structural trust

Agents decide from typed fields — safety level, confirmation, destructive — never from free text alone.

Signed manifests

HMAC-SHA256 over a canonical payload, bound to your domain. Tampering is detected.

Injection sanitising

Every string field is checked for prompt injection and length-limited before an agent sees it.

Single-use tokens

Each agent action carries a short-lived token that is rejected on replay.

Abstract conditions

Contracts say user.hasPaymentMethod, never your database fields.

Zero dependencies

The core package ships no runtime dependencies — a smaller supply-chain surface.

Quick start

Add it in minutes

Wrap your app in a provider and attach a contract. Intent defaults fill in the rest: place-order is high risk and needs confirmation automatically.

Using VhyxUI? Its components already carry contracts — no extra code.

import { SealProvider, Button } from "@vhyxseal/react";
import { defineContract } from "@vhyxseal/core";

const placeOrder = defineContract({
  id: "place-order",
  type: "action",
  intent: "place-order",
  description: "Places the current cart as an order",
  consequence: "Creates an order and charges the saved card",
  affects: ["orders", "payments"],
  requires: [], requiredPermissions: [], contractVersion: "1.0.0",
});

<SealProvider config={{ domain: "example.com", domainVerified: false, verificationToken: "" }}>
  <Button contract={placeOrder} onClick={submitOrder}>Place order</Button>
</SealProvider>
Packages

Works where you work

One contract schema across frameworks, tooling and tests.

@vhyxseal/coreSchema, inference, manifests, signing. Zero dependencies.
@vhyxseal/reactSealProvider, withAgentContract, hooks, headless components.
@vhyxseal/vueVue 3 plugin, composables and components.
@vhyxseal/vanillaCustom elements for any framework, safe during SSR.
@vhyxseal/nextjsConfig plugin and the manifest route handler.
@vhyxseal/cliinit, simulate, verify, audit, diff, keygen, sign, visualize.
@vhyxseal/devtoolsIn-page panel to inspect every contract.
@vhyxseal/testingMatchers, drift detection and a mock agent.

Make your UI safe for agents

Give every component a contract, publish a signed manifest, and keep people in control.