2AYE
2AYE community

Build the boundary agents cannot talk their way around.

2AYE is developed in the open around one non-negotiable rule: model output is untrusted input. Human-signed authority and deterministic enforcement decide what executes.

Open the contributor guide Read the architecture
Contribution paths

Choose the layer you can make stronger.

Enforcement adapters

Put verification at the protected resource. New adapters must refuse missing, forged, expired, replayed, or parameter-mismatched grants.

Security research

Turn attacks into reproducible rejection tests. Responsible disclosure stays private until a fix is available.

Specification and standards

Improve schemas, canonical vectors, predicate definitions, OAuth mappings, and cross-authority trust models.

Product and documentation

Make consequential authority understandable to operators, approvers, auditors, and tool builders.

The review contract

Security changes carry evidence.

A green test suite is necessary and insufficient. Every authorization change explains which invariant it preserves and includes a test proving the bypass stays closed.

  1. OrientRead the architecture, living specification, and contribution guide.
  2. ProposeOpen an issue for material protocol, schema, or trust-boundary changes.
  3. ProveAdd acceptance and rejection evidence, including failure paths.
  4. ReviewSecurity-sensitive changes require maintainer review and honest story status.

Your first contribution should be small enough to prove.

Pick one open gap, one adapter boundary, or one rejection case. Make the authority model clearer when you leave than when you arrived.

Review the contribution contract
Your governed workflow

Bring the next consequential action under control.

Show us the actor, protected resource, and action that must never execute without exact authority. We’ll map the decision and evidence path with you.

Discuss your workflow Read the implementation guide
2AYE Community | Build enforceable agent authority