Experimental open contract between websites and AI agents (Open Agent Access Gateway)
TypeScript
0
4 commits
updated Oct 1, 2026
Experimental draft. Not a standard. Not security-audited.
A proposed open contract between websites and AI agents, with a small reference implementation in Node.js/TypeScript.
About the name: Windi means "concession, courtyard" in Songhay: an enclosed compound whose owner decides who may enter, and how far.
Websites block AI agents because open access is risky. Agents hit a bare refusal and learn nothing. Windi proposes a middle path:
anonymous, verified, partner);Windi reuses existing work (Web Bot Auth, HTTP Message Signatures, ARD, MCP, RFC 9457) instead of inventing new identity or discovery formats.
SPEC.md: the specification draft v0.1.src/: reference implementation (signature verification, tiers, capabilities, rate limits, audit log, HTTP adapter).examples/: a fictional site with 5 capabilities, and a simulation of three AIs.test/: automated tests for the specification's test cases and extra security checks.Requires Node.js 20 or later.
npm install
npm test # runs the test suite
npm run demo # starts the demo site and lets 3 simulated AIs call it
The demo prints each request's result and the resulting audit log.
npm run demo starts a fictional site and lets three simulated agents call it. Real output:
anonymous -> public-articles 200 OK
anonymous -> article-full 403 Access level too low for this capability (your_tier=anonymous, available=["public-articles","site-search"])
verified -> article-full 200 OK
verified -> request-callback 403 Access level too low for this capability (your_tier=verified, available=[...])
partner -> request-callback 200 OK
stranger -> catalog-query 403 Access level too low for this capability (your_tier=anonymous, available=["public-articles","site-search"])
Audit log:
anonymous null public-articles news allowed
anonymous null article-full news denied (tier-too-low)
verified verified-ai article-full news allowed
verified verified-ai request-callback support denied (tier-too-low)
partner partner-ai request-callback support allowed
anonymous stranger-ai catalog-query catalog denied (tier-too-low)
Note how a denied agent is told what it can access, and every call, allowed or not, lands in the audit log.
Windi is not meant to replace these. It sits at a different layer.
In short: existing work covers identity and discovery; Windi proposes the missing middle, a declared, tiered, auditable contract with refusals that explain themselves.
Policy (see examples/demo-site.ts).verified / partner lists.Gateway, and plug gateway.handle(request) into your framework, or use createGatewayServer for plain node:http.Read these before using it for anything real.
Signature-Agent, because that requires SSRF protections that are not implemented yet.Content-Digest yet).ai-subject-id header) is a proposal: no standard carries it today.Open an issue to discuss, or a pull request to propose changes. Especially welcome:
Content-Digest support and machine-readable test vectors;src/, test/, examples/): MIT License.SPEC.md): Creative Commons Attribution 4.0 International (CC BY 4.0). You may reuse and adapt it, including commercially, if you give credit and indicate changes.Copyright (c) 2026 MAIGUS.
The reference implementation has no runtime dependencies. Development tools (TypeScript, tsx, @types/node) are used only to build and test and are under their own licenses (Apache-2.0 and MIT).
LICENSE).Please report vulnerabilities privately, as described in SECURITY.md. Contribution rules are in CONTRIBUTING.md.
Windi propose un contrat ouvert entre les sites web et les agents d'IA, avec une petite implémentation de référence en Node.js/TypeScript.
À propos du nom : Windi signifie « concession, cour » en songhay : un espace clos dont le maître des lieux décide qui entre, et jusqu'où.
Beaucoup de sites bloquent totalement les IA, car un accès libre est risqué et il n'existe pas de solution intermédiaire. Les IA, de leur côté, se heurtent à un simple refus sans savoir ce qui leur serait accessible.
L'idée :
anonymous (non reconnue), verified (acceptée par le site), partner (liée au site) ;Le projet s'appuie sur des travaux existants (Web Bot Auth, signatures HTTP, ARD, MCP) plutôt que d'inventer de nouveaux formats.
Essayer : npm install, puis npm test (tests) et npm run demo (trois IA simulées appellent un site fictif).
Limites à connaître : ce n'est pas un standard, la sécurité n'a pas été auditée, les clés des opérateurs sont lues dans un répertoire local, le corps des requêtes n'est pas signé, et une signature valide prouve qui a signé la requête, pas que l'utilisateur derrière l'IA est de bonne foi.
Licences : code sous licence MIT ; texte de la spécification sous licence Creative Commons Attribution 4.0 (CC BY 4.0). Fourni « tel quel », sans garantie. Les noms de produits et de protocoles cités appartiennent à leurs propriétaires ; ce projet est indépendant et non affilié.
Statut : brouillon de spécification (SPEC.md) et implémentation de référence expérimentale. Les contributions sont les bienvenues.
TypeScript
100.0%
Experimental open contract between websites and AI agents (Open Agent Access Gateway)
TypeScript
0
4 commits
updated Oct 1, 2026
Experimental draft. Not a standard. Not security-audited.
A proposed open contract between websites and AI agents, with a small reference implementation in Node.js/TypeScript.
About the name: Windi means "concession, courtyard" in Songhay: an enclosed compound whose owner decides who may enter, and how far.
Websites block AI agents because open access is risky. Agents hit a bare refusal and learn nothing. Windi proposes a middle path:
anonymous, verified, partner);Windi reuses existing work (Web Bot Auth, HTTP Message Signatures, ARD, MCP, RFC 9457) instead of inventing new identity or discovery formats.
SPEC.md: the specification draft v0.1.src/: reference implementation (signature verification, tiers, capabilities, rate limits, audit log, HTTP adapter).examples/: a fictional site with 5 capabilities, and a simulation of three AIs.test/: automated tests for the specification's test cases and extra security checks.Requires Node.js 20 or later.
npm install
npm test # runs the test suite
npm run demo # starts the demo site and lets 3 simulated AIs call it
The demo prints each request's result and the resulting audit log.
npm run demo starts a fictional site and lets three simulated agents call it. Real output:
anonymous -> public-articles 200 OK
anonymous -> article-full 403 Access level too low for this capability (your_tier=anonymous, available=["public-articles","site-search"])
verified -> article-full 200 OK
verified -> request-callback 403 Access level too low for this capability (your_tier=verified, available=[...])
partner -> request-callback 200 OK
stranger -> catalog-query 403 Access level too low for this capability (your_tier=anonymous, available=["public-articles","site-search"])
Audit log:
anonymous null public-articles news allowed
anonymous null article-full news denied (tier-too-low)
verified verified-ai article-full news allowed
verified verified-ai request-callback support denied (tier-too-low)
partner partner-ai request-callback support allowed
anonymous stranger-ai catalog-query catalog denied (tier-too-low)
Note how a denied agent is told what it can access, and every call, allowed or not, lands in the audit log.
Windi is not meant to replace these. It sits at a different layer.
In short: existing work covers identity and discovery; Windi proposes the missing middle, a declared, tiered, auditable contract with refusals that explain themselves.
Policy (see examples/demo-site.ts).verified / partner lists.Gateway, and plug gateway.handle(request) into your framework, or use createGatewayServer for plain node:http.Read these before using it for anything real.
Signature-Agent, because that requires SSRF protections that are not implemented yet.Content-Digest yet).ai-subject-id header) is a proposal: no standard carries it today.Open an issue to discuss, or a pull request to propose changes. Especially welcome:
Content-Digest support and machine-readable test vectors;src/, test/, examples/): MIT License.SPEC.md): Creative Commons Attribution 4.0 International (CC BY 4.0). You may reuse and adapt it, including commercially, if you give credit and indicate changes.Copyright (c) 2026 MAIGUS.
The reference implementation has no runtime dependencies. Development tools (TypeScript, tsx, @types/node) are used only to build and test and are under their own licenses (Apache-2.0 and MIT).
LICENSE).Please report vulnerabilities privately, as described in SECURITY.md. Contribution rules are in CONTRIBUTING.md.
Windi propose un contrat ouvert entre les sites web et les agents d'IA, avec une petite implémentation de référence en Node.js/TypeScript.
À propos du nom : Windi signifie « concession, cour » en songhay : un espace clos dont le maître des lieux décide qui entre, et jusqu'où.
Beaucoup de sites bloquent totalement les IA, car un accès libre est risqué et il n'existe pas de solution intermédiaire. Les IA, de leur côté, se heurtent à un simple refus sans savoir ce qui leur serait accessible.
L'idée :
anonymous (non reconnue), verified (acceptée par le site), partner (liée au site) ;Le projet s'appuie sur des travaux existants (Web Bot Auth, signatures HTTP, ARD, MCP) plutôt que d'inventer de nouveaux formats.
Essayer : npm install, puis npm test (tests) et npm run demo (trois IA simulées appellent un site fictif).
Limites à connaître : ce n'est pas un standard, la sécurité n'a pas été auditée, les clés des opérateurs sont lues dans un répertoire local, le corps des requêtes n'est pas signé, et une signature valide prouve qui a signé la requête, pas que l'utilisateur derrière l'IA est de bonne foi.
Licences : code sous licence MIT ; texte de la spécification sous licence Creative Commons Attribution 4.0 (CC BY 4.0). Fourni « tel quel », sans garantie. Les noms de produits et de protocoles cités appartiennent à leurs propriétaires ; ce projet est indépendant et non affilié.
Statut : brouillon de spécification (SPEC.md) et implémentation de référence expérimentale. Les contributions sont les bienvenues.
TypeScript
100.0%