Connect an agent to automated policy enforcement.

Add HaltState at one backend tool or API action, then configure and activate the policies it will enforce. Start with one integration and expand when ready.

You are connecting an enforcement point—not creating a queue that requires someone to approve every action.

Create your workspace online—no enterprise enquiry is required. Already registered? Sign in.

From connection to automatic enforcement

  1. Create your HaltState account and get your workspace credentials.
  2. Connect a supported tool or API action using the SDK instructions below.
  3. Use the AI Policy Assistant to help draft policies, then review and activate them through the existing policy flow.
  4. Confirm automatic allow and automatic deny, then test a policy-required approval case.
  5. Connect your MCP client to search activity, inspect recorded outcomes and verify evidence without returning to the dashboard for each investigation.

See how it works

Installation video

Watch the installation walkthrough

This is the primary operator video: install the SDK, wrap one high-risk action, and inspect the HaltState decision before the business system is touched.

Watch HaltState installation video on YouTube

Install with a coding agent

Use this route when you want Codex, Claude Code, or Cursor to add the first guarded action in a branch, show the diff, and stop before deployment.

Codex

Use the generated prompt to add one guarded action, tests, and a reviewed diff.

Claude Code

Use the same bounded prompt with environment variables and no infrastructure changes.

Cursor

Use the prompt inside your repo and require tests before merge.

Python coding-agent prompt

You are adding HaltState to one Python backend action only.

Install the released package inside the backend service:
pip install haltstate-sdk

Use HALTSTATE_TENANT_ID and HALTSTATE_API_KEY from environment variables only.
Keep keys out of browser code, frontend bundles, logs and committed files.
Identify one backend side-effecting action, such as refund.create, payment.authorize, customer.message.send, PII export or a production write.
Wrap/check/report that one action with the current Python SDK.
Guard the selected action before the side effect executes.
The released Python package uses the live Standard contract. Use a stable logical idempotency key for HaltState and keep a separate stable destination idempotency key.
Do not construct an hsr1 replay key or claim replay-safe permits and receipts with the released package.
Only if an operator separately authorises the replay candidate, install the published 0.8.0.dev1 release and use the assigned activation epoch.
Handle ALLOW, APPROVAL_REQUIRED and DENY explicitly.
On ALLOW, execute the side effect once and report success or failure after the business action completes.
On APPROVAL_REQUIRED, do not execute; persist or return the pending state for human review.
On DENY, do not execute and record the denial safely.
Fail closed on HaltState auth or transport errors for money, PII and production writes.
Add or update tests for allowed, approval-required, denied and HaltState-unavailable paths.
Show the diff and stop for human review.
Do not deploy or change infrastructure.

TypeScript coding-agent prompt

You are adding HaltState to one TypeScript backend action only.

Install the released package inside the backend service:
npm install @haltstate/sdk

Use HALTSTATE_TENANT_ID and HALTSTATE_API_KEY from environment variables only.
Keep keys out of frontend/browser code, logs and committed files.
Identify one backend side-effecting action, such as refund.create, payment.authorize, customer.message.send, PII export or a production write.
Wrap/check/report that one action with the current TypeScript SDK.
If you use the helper, call withGuard(action, options, fn).
withGuard performs reporting and should not be manually duplicated.
For explicit reporting, pass the CheckResult to report with status success, failure or error.
Guard the selected action before the side effect executes.
The released TypeScript package uses the live Standard contract. Use a stable logical idempotency key for HaltState and keep a separate stable destination idempotency key.
Do not construct an hsr1 replay key or claim replay-safe permits and receipts with the released package.
Only if an operator separately authorises the replay candidate, install the published 2.0.0-dev.0 release and use the assigned activation epoch.
Handle ALLOW, APPROVAL_REQUIRED and DENY explicitly.
On ALLOW, execute the side effect once and report success or failure after the business action completes.
On APPROVAL_REQUIRED, do not execute; persist or return the pending state for human review.
On DENY, do not execute and record the denial safely.
Fail closed on HaltState auth or transport errors for money, PII and production writes.
Add or update tests for allowed, approval-required, denied and HaltState-unavailable paths.
Show the diff and stop for human review.
Do not deploy or change infrastructure.

First-action answers before you paste the prompt

What am I protecting?

Pick one backend action that changes business state: a refund, payment, customer message, PII export, production write, account change, or infrastructure operation.

Which SDK should I use?

Use the SDK that matches the service executing the action. Python and TypeScript are the most common first installs; Go, Java, and Rust are supported paths for backend services.

How do I install it?

Install the package inside the backend service or worker, then add the guard immediately before the side effect. Do not put HaltState API keys in browser JavaScript.

Where do tenant ID and API key come from?

Create your workspace at HaltState signup, then use its tenant ID and API key as server-side environment variables. Existing customers can sign in at /haltstate/login. No enterprise form is required to start.

What should I paste into Codex, Claude Code, or Cursor?

Paste the Python coding-agent prompt, TypeScript coding-agent prompt, or the prompt generated by triage. It requires HALTSTATE_API_KEY, HALTSTATE_TENANT_ID, environment variables only, stable idempotency keys, fail-closed handling, tests, diff review, and no deploy or infrastructure changes.

What do I do after the first guarded action works?

Review the diff and tests, confirm ALLOW / APPROVAL_REQUIRED / DENY behavior, then create, review, and activate production policies inside onboarding and the Policy Assistant.

Install manually

Choose Python, TypeScript/JavaScript, Go, Java or Rust. All five SDKs are published through the distribution links below. Run them in a backend service, worker or trusted server-side tool wrapper, with credentials in environment variables.

SDKPublished releasesDistribution
Python SDKStable 0.7.0; recording and Semiotic Probe release 0.8.0.dev1pip install haltstate-sdk
PyPI: 0.8.0.dev1
TypeScript SDK / JavaScriptStable 1.0.2; Semiotic Probe release 2.0.0-dev.0 on the next channelnpm install @haltstate/sdk
npm install @haltstate/sdk@next
Go SDKStable v1.0.1; recording and Semiotic Probe release v1.1.0-dev.1GitHub / Go module
go get github.com/haltstate-ai/sdk-go@v1.1.0-dev.1
Java SDKRecording and Semiotic Probe release v0.3.0-dev.1GitHub / JitPack
Rust SDKRecording and Semiotic Probe release v0.2.0-dev.1GitHub Cargo dependency

All five SDKs are available. Select the documented release for the features you need; development-version releases are installed explicitly. The additional TypeScript recording helpers are not in the published 2.0.0-dev.0 release. Installing an SDK does not change your workspace's runtime contract. Existing integrations continue to use the Standard contract; replay-enabled integrations use the configured replay contract.

Environment variables

HALTSTATE_TENANT_ID and HALTSTATE_API_KEY are available after self-service signup. Keep them server-side. Hands-on SDK installation should be handled with the coding-agent prompt or your internal engineering workflow. The Enterprise path is optional for private deployments, fleet requirements or a commercial discussion—not a prerequisite for an account.

HALTSTATE_TENANT_ID=your-tenant-id
HALTSTATE_API_KEY=hs_your_api_key
HALTSTATE_API_BASE=https://haltstate.ai

Minimal Standard-contract refund.create guard

This example uses the released Python package and the live Standard contract. Use the replay-enabled SDK contract only under separate operator authorisation.

from haltstate import HaltStateClient, ApprovalPending, ActionDenied

client = HaltStateClient(
    tenant_id=os.environ["HALTSTATE_TENANT_ID"],
    api_key=os.environ["HALTSTATE_API_KEY"],
)
logical_key = "refund:order-1001"

try:
    with client.guard(
        action="refund.create",
        params={"amount": 126, "currency": "USD"},
        idempotency_key=logical_key,
    ):
        simulated_ledger.write_refund(idempotency_key=logical_key)
except ApprovalPending:
    queue_for_review()
except ActionDenied:
    do_not_refund()

Safe operator example

HALTSTATE_REFUND_AGENT_API_KEY=$HALTSTATE_API_KEY   python services/retail_refund_agent.py --once

What to verify first

What happens after the SDK connects

  1. The agent/action is detected or registered.
  2. The onboarding wizard guides scope and risk selection.
  3. The AI Policy Assistant drafts policies.
  4. A human reviews and publishes.
  5. HaltState enforces actions and records Proof Packs.

The public triage page can prepare a starter action map and coding-agent prompt, but it never activates production policy.

Use your MCP client for everyday investigation

After your agents are connected, add https://haltstate.ai/mcp to a compatible client and authorize your account. Ask what an agent did, find a customer interaction, follow its timeline or verify a Proof Pack from the client you already use.

Compatible clients renew access automatically; you do not need to sign in to the dashboard for every investigation. Account setup, policies, approvals, containment, billing and connection permissions remain in the dashboard. MCP investigation does not replace SDK enforcement.

Connect your MCP client

Recommended path

Start with one action that has clear business impact and clear authority rules. Refunds are ideal for retail teams because the thresholds are understandable: small clean refunds can pass, medium refunds can require approval, and duplicates or high-value refunds can be denied. After that first action is stable, add customer data access, outbound messages, production writes, or payment authorization.

Keep the first implementation boring. Put the guard in a backend service or worker, not in public browser code. Store credentials in environment variables or a secrets manager. Derive the idempotency key before the guard call. Fail closed for money, PII, and production writes. Report success only after the business action actually completes.

More walkthroughs.

Use these videos when moving from the public overview into SDK setup, runtime policy review and operator evidence checks.

Existing product walkthrough

When policy requires human approval

Watch When policy requires human approval on YouTube

This part of the walkthrough shows the exception path. Permitted actions can proceed automatically, and prohibited actions are blocked automatically.

Reviewing a policy during setup is not the same as approving every action at runtime.