Skip to main content
Release candidate · React, Vue, vanilla, Next.js · MIT

Seal the contract between your UI and the agentic web.

AI agents now use websites for people — but they only see pixels. VhyxSeal gives every component a machine-readable contract: what it does, how risky it is, and when a human must confirm.

npm install @vhyxseal/react @vhyxseal/core

Agents are guessing

A web page was built for eyes. An agent reading it has to infer everything that matters.

What does it do?

A button labelled “Continue” could save a draft or charge a card.

How risky is it?

Nothing in the markup says an action is destructive or irreversible.

Who must approve?

There is no standard way to say “a person has to confirm this”.

One component, two audiences

Nothing changes for people. Agents get a precise, typed contract — OpenAPI for your UI.

What a person sees

To a person, these are three buttons. Choose one to see what an AI agent reads for it.

What an agent reads

highhuman confirms
{
  "id": "place-order",
  "intent": "place-order",
  "safetyLevel": "high",
  "requiresConfirmation": true,
  "destructive": false,
  "reversible": true,
  "consequence": "Creates an order and charges the saved card"
}

Generated live by defineContract() from @vhyxseal/core.

How an agent uses your site

Your site publishes every contract as a signed manifest at /__agent__/manifest.json. The agent verifies the signature, acts freely on low-risk actions, and stops to ask a person before anything that needs confirmation. Each action carries a single-use token.

This page publishes its own manifest — try /__agent__/manifest.json. Diagram by VhyxChart.

Security is the foundation, not a feature

VhyxSeal sits between agents and your site, so every layer assumes the one above it can fail.

  • Structural trust

    Agents decide from typed fields — safety level, confirmation, destructive — never from free text alone.

  • Signed manifests

    HMAC-SHA256 over a canonical payload, bound to your domain. Tampering is detected.

  • Injection sanitising

    Every string field is checked for prompt injection and length-limited before an agent sees it.

  • Single-use tokens

    Each agent action carries a short-lived token that is rejected on replay.

  • Abstract conditions

    Contracts say user.hasPaymentMethod, never your database fields.

  • Zero dependencies

    The core package ships no runtime dependencies — a smaller supply-chain surface.

Add it in minutes

Wrap your app in a provider and attach a contract. Intent defaults fill in the rest: place-order is high risk and needs confirmation automatically.

Using VhyxUI? Its components already carry contracts — no extra code.

import { SealProvider, Button } from "@vhyxseal/react";
import { defineContract } from "@vhyxseal/core";

const placeOrder = defineContract({
  id: "place-order",
  type: "action",
  intent: "place-order",
  description: "Places the current cart as an order",
  consequence: "Creates an order and charges the saved card",
  affects: ["orders", "payments"],
  requires: [], requiredPermissions: [], contractVersion: "1.0.0",
});

<SealProvider config={{ domain: "example.com", domainVerified: false, verificationToken: "" }}>
  <Button contract={placeOrder} onClick={submitOrder}>Place order</Button>
</SealProvider>

Works where you work

One contract schema across frameworks, tooling and tests.

@vhyxseal/core

Schema, inference, manifests, signing. Zero dependencies.

@vhyxseal/react

SealProvider, withAgentContract, hooks, headless components.

@vhyxseal/vue

Vue 3 plugin, composables and components.

@vhyxseal/vanilla

Custom elements for any framework, safe during SSR.

@vhyxseal/nextjs

Config plugin and the manifest route handler.

@vhyxseal/cli

init, simulate, verify, audit, diff, keygen, sign, visualize.

@vhyxseal/devtools

In-page panel to inspect every contract.

@vhyxseal/testing

Matchers, drift detection and a mock agent.

Part of the Vhyxara family

VhyxUI

Components

Accessible React components with VhyxSeal contracts built in.

Learn more →

VhyxSeal

Agents

The contract layer between your UI and AI agents.

Learn more →

VhyxChart

Diagrams

Animated diagrams — vhyxseal visualize draws your contracts.

Learn more →

Make your UI safe for agents

Give every component a contract, publish a signed manifest, and keep people in control.