CAIN-42 CAIN Studio

Developer documentation

CAIN-42 today

Last reviewed 31 August 2026

All docs

The state of the technology as of 1 October 2026, in one page. Every statement here was checked against the live sites or the code on that date. When something is not live, this page says so.

CAIN stands for Cognitive Artificial Intelligence Network. It sits between an autonomous AI agent and the consequential things it does (tool calls, payments, record changes), decides on each action *before* it runs, has that decision certified by a quorum of independent nodes, and leaves a signed record you can verify without trusting us.

What you can use right now#

SurfaceWhereStatus
Decision APIPOST https://cainstudio.online/fabric/decisions (API key)Live
Demo, no accountPOST https://cainstudio.online/fabric/try?scenario=safe-readLive, 20 requests per hour per address
Python SDK cainstudiopip install https://cainstudio.online/cainstudio-0.3.0-py3-none-any.whlLive (hosted wheel; not on PyPI yet)
LangChain / LangGraphcainstudio.langchain.protect([...])Live (in the SDK)
TypeScriptcopy the helper in TypeScriptNo npm package yet
MCPGate (MCP proxy)MCP, Self-hostedLive hosted; self-hosted via Helm
Signed decision recordsDecision record format, /verify.htmlLive; verify offline
Free signup/signupLive (per-address rate limit; no captcha yet)
Book a demo/book-demoLive

How a decision is made#

Send the tool call before you run it. CAIN runs it through this chain, in order, and returns every stage's verdict. The stage names below are the ones in every response.

#StageWhat it checks
1identityWho is asking: the API key resolves to a principal (a service or a named agent key).
2intentThe intent the caller declared for this action (recorded; not enforcing on its own).
3policyYour policy (OPA) allows this path and payload.
4authorizationThe account's entitlement is active.
5riskKnown attack patterns (prompt injection, exfiltration shapes) and the action's risk level.
6trustThe agent's earned trust for this kind of action. Unknown trust never becomes ALLOW by itself.
7verificationIf you submitted a plan, its structure is checked.
8actionproofIf you submitted a plan, ActionProof checks it before any step runs.
9approvalWhether a human must approve; if so the call is held with an approval id.
10consensusThe decision is ordered and certified by 3 of the 4 nodes of the PBFT cluster.
11egressNetwork destinations named in the action are inside your allowlist (observe-only until you add a rule).
12toolargsArguments match the tool's registered schema (observe-only for tools without a schema).
13artifactsPinned, publisher-signed tools, skills and MCP servers; dangerous capability combinations.
14enforcementWhere the verdict lands (the hosted gateway, MCPGate or the SDK guard).
15executionWhether the call may execute: allowed, held, or prevented.
16outcomeThe action's lifecycle state.
17evidenceThe decision is recorded, signed, and bound to a hash of the exact arguments.

Stages 11 to 13 run after consensus and can only add a denial, never an allow. If one of them cannot run, it denies (fail-closed).

The rule for callers: run the tool only when verdict starts with ALLOWED and blocked is false. Everything else, including a timeout and a non-200 response, means "do not run". A new agent's first actions usually come back REQUIRE_APPROVAL.

Speed#

A hosted decision currently takes about 0.7 to 1.0 seconds, of which about 650 ms is the consensus round (measured 2026-10-01; see Benchmarks). An owner can put an agent on the snapshot fast path (POST /fabric/agent-keys/{id}/fast-path), which checks a quorum-committed authorization snapshot instead of waiting for a round. That path is enabled in production but has not yet been measured end to end for a customer agent.

The cluster#

The live consensus cluster cain-mr-02 has 4 nodes in Atlanta, Los Angeles, Miami and San Jose, all on one hosting provider, and survives the loss of any one node. It publishes signed agreement proofs every hour; see /live-cluster.html.

What is not live#

Be precise about these when you build on CAIN:

  • Not on PyPI or npm. Use the hosted wheel above, or the HTTP API directly.
  • CAIN is a decision point unless you route calls through it. An agent that

calls a tool without asking CAIN is not stopped by CAIN. MCPGate and the SDK guard are how the verdict becomes enforcement.

  • Evolutions E9 to E42 are tested libraries, most of them not on the hosted

decision path. Their evidence bundles say so.

  • /fabric/frontier/* was withdrawn on 2026-10-01 (unauthenticated writes to

a shared store) and returns 404.

  • No third-party audit or certification yet, and no independent reproduction

of the evidence. See what we do not do yet.

  • Demo requests are stored but not emailed until notification is configured.

Where to go next#

1. Quickstart: a first decision in five minutes. 2. Python SDK: @cainstudio.guard(), approvals, runs. 3. Use with your existing stack: LangChain, OpenAI Agents, CrewAI, MCP. 4. Decision record format: verify a decision offline. 5. 7-Moat architecture: the seven layers behind all of this. 6. Changelog: what changed and when.