
Every agent tool call stops at the gate.
A starter kit in Kinde's official starter-kits organization. It checks every AI agent tool call before it runs. Kinde answers who the agent acts for and what that user can do. Jev, the System One model from TypeSafe AI, answers whether the user asked for the call. Policy code then allows the call, holds it for a fresh sign-in, or stops it.
- 01KindeSigns the user in and passes their token through a Kinde MCP connection. The guard reads the organization, permissions, and feature flags.
- 02JevReads the call, the request, and the documents the agent read. It returns typed signals in about 200 ms.
- 03PolicyCode decides from the signals. It writes the decision to a ledger before anything runs.
Benchmark: 300 labeled tool calls, run 3 times each

