Developer documentation
The ecosystem and library
Last reviewed 31 August 2026
All docs
The CAIN-42 ecosystem and library#
Everything CAIN-42 offers is on one page: the Everything in CAIN-42 section of each homepage (cainstudio.online, mcpgate.online and clawx.click). It is a menu you can search and scroll. Every product links to its own page, and every piece of evidence has its own page in the library.
How the ecosystem menu is organised#
Products are grouped by what you want your AI agents to do safely:
- Start here: the sandbox, the live demo, the playground and the AI quickstart. You need no card.
- Stop risky actions: Control, Governance, tool rules, approvals, the kill switch, Budget, Agent Security and prompt-injection inspection.
- See what your agents do: Observability, Trace, Trajectory, Drift, Sentinel and MCPWatch.
- Inside your free account: the console views (agents, live decisions, traces, policy lab, webhooks, team, API keys and billing).
- Secure tools & MCP servers: MCPGate, the MCP Security Scanner, DriftGuard, ToolWarden, MCPiverse and the MCP Explorer.
- Protect identities, keys & data: Identity, the credential broker, LeakGuard, Memory and Private.
- Test & grade your AI: AgentScore, ProbeGate, Verifygate, Fairgate, Citegate, Liftgate and the red-team tooling.
- Prove it to anyone: Proof, Compliance, the EU AI Act portal, the Trust Center, the offline verifiers and the decision signing key.
- For developers: the Python and TypeScript SDKs, the CLI, the MCP server, the Decision API and framework integrations.
- For large organisations: SSO and SCIM, SIEM forwarding, self-hosting, the appliance and advisory services.
- How it works: the 7 moats, the live consensus cluster, the Frontier Lab and the changelog.
- Coming next: product lines in development. Their code is tested but not yet hosted or sold, and their pages say so.
Search the menu in plain words, for example "stop my agent deleting files" or "keep my API keys safe". Matching runs in your browser and uses keywords and synonyms. What you type is never sent anywhere.
Product pages#
Each product has a page at /products/<name>, for example /products/control. A page shows:
- what the product does, in plain terms and in technical terms;
- its status: Live, Enterprise or In development;
- links to the product, its documentation, API and MCP endpoints;
- its full documentation, when the product has some;
- for engineers, the Python SDK, MCP and Decision API setup.
Three panels are live:
- Live now: your browser checks the product's links when the page opens and shows the HTTP status
and the time taken. When an API answers publicly, its current response is shown too.
- Fire a real decision: sends a real action through the live CAIN-42 pipeline, with no account,
using a throwaway demo tenant. You see every stage's verdict, the consensus cluster and sequence, the quorum certificate digest, and whether the stored record's digest matches. It is rate limited.
- Tested guarantees in this area: links to the library niches whose tested rules back this kind of product.
The library#
The library is at /explore. It holds one page for every evidence bundle, every published claim (including the signed public claims registry) and every tested invariant. An invariant is a rule the system must never break. Every page is read from the published evidence files themselves, so it always says exactly what the evidence says. New bundles appear in the library automatically.
Invariants are grouped into 14 niches, each at /explore/niche/<key>:
- Consensus & distributed systems
- Attacks, threats & containment
- Identity, authority & delegation
- Evidence, receipts & proofs
- Memory, data & privacy
- Prediction, world models & simulation
- Transactions, markets & economics
- Tools, MCP, protocols & adapters
- Autonomy, control loops & recovery
- Policy, law & governance
- Trust & reputation
- Supply chain, registry & lifecycle
- Benchmarks, coverage & performance
- Core guarantees
Searching every page#
Every library page has a search bar at the top. Press Ctrl+K (or Cmd+K on a Mac) and type a few words, for example "revoked credential" or "quorum". The bar also shows a live status pill for the consensus cluster that signs decisions. The homepages have the same search in their Library block.
Machine-readable indexes:
/explore/search.json: every page, compact./explore/sitemap.xml: every page URL./explore/llms.txt: a guide to the library written for AI agents.- Add
?format=jsonto any product, bundle, niche, family, invariant or claim page to get the same content
as structured JSON. The top bar of every library page links to it.
Verifying evidence in your browser#
Bundle, invariant and claim pages have a Verify it in your browser button. Your browser:
1. downloads the bundle's SHA256SUMS manifest and the files behind the page; 2. hashes them locally with SHA-256 (WebCrypto) and compares; 3. on invariant and claim pages, reads the exact record from the file it just hashed.
A match shows that the record you are reading is the published one. It does not by itself prove who published it. For that, use the signed claims registry and each bundle's standalone verifier (REPRODUCTION.md in the bundle).
Subdomains#
Every library page has a short label. When DNS for the label is in place, the page is served at https://<label>.cainstudio.online/. Examples:
control.cainstudio.onlineis a product.niche-attacks.cainstudio.onlineis a niche.e40.cainstudio.onlineis an evidence bundle.e40-i40-001.cainstudio.onlineis one invariant.
The canonical address of every page stays its /products or /explore path.