Skip to main content

DEVELOPERS / RUST-FIRST

One contract. From your terminal to your agent tools.

Keep your runtime and business rules. Start from exact History, inspect State changes, and explore validated local Turn Frames built on the same Rust decision core.

LOCAL TOOLKIT / REVIEW CANDIDATE

Profile State. Prepare a turn. Keep live effects outside.

Native toolkit 0.1.0 is an unmerged review candidate, locally qualified on Linux x64. No public binary release, macOS/Windows distribution, or live AWS connection is offered here.

Local candidate · in review
Native toolkit candidate workflow
# Review candidate only. Use an approved Linux x64 artifact.
# No public installer is available. These commands run locally.
kam init --template deployment-agent
kam init --template deployment-agent --write
kam doctor --json
kam generate --check
kam dev --json
kam replay --scenario invalidated --json
kam atlas --scenario corrected --json
kam qualify --json

Real semantics. Local reference-only turns.

The candidate shares the service’s Rust History and State code, profiles definition/membership/provenance/fence changes, and creates validated local Turn Frames without calling AWS or a model.

A prepared frame is not a live model request, committed Turn Receipt, authorization check, provider cache hit, or external action.

Read the Turn Lifecycle boundary ↗

SDK / CANDIDATE 0.31.0

Bind the scope once. Keep the exact references.

The SDK is an ergonomic adapter, not a second policy engine. It is source-implemented but not publicly published to npm.

Scoped, generation-bound History read
// Save as a .mjs file in an authorized backend source checkout. SDK candidate 0.29.0.
// This is a read-only example, not code executed by the website.
import { createKamClient } from './server/trajectory/sdk/index.mjs';
const kam = createKamClient({
  baseUrl: process.env.KAM_API_URL,
  tenantId: process.env.KAM_TENANT_ID,
  accessToken: () => process.env.KAM_ACCESS_TOKEN,
});
const deployments = kam.scope({ subjectId: 'checkout', type: 'deployment' });
const page = await deployments.allIds({ day: '2026-10-06', limit: 16 });
if (page.status === 'ready' && page.items.length > 0) {
  const exact = await deployments.byIds({
    day: page.day,
    generation: page.generation,
    refs: page.items,
  });
  console.log(exact.records); // Keep every position and result status.
}
// A short page is not the end when nextCursor is present.
// Continue with the SAME generation and returned cursor.

ONE NAMESPACE

Know what each command can change.

Configure

init · config · generate · doctor · env

Plan-first local files and diagnostics. kam doctor is not the remote kam-history doctor.

Exercise

dev · state · replay · atlas · preview · qualify

Synthetic observations and the actual Rust engine. No live source calls, agent replay, or token estimates.

Inspect & explain

inspect · docs · skills · mcp · capabilities

Private local reports and read-only agent tools. No hosted console or public share link.

Plan integration

connect agentcore · promote · rollback

Reviewable connection and local channel plans only. No Gateway attachment or remote rollout.

THE IMPLEMENTATION BEHIND THE INTERFACE

Centralize contracts. Keep responsibilities separate.

Shared definitions reduce drift; narrow adapters prevent a read command from quietly becoming a writer.

One command contract

CLI options, help, and the explicit MCP subset come from one typed Rust catalog. A new CLI command is not automatically an agent tool.

One application read path

The CLI and MCP share query handlers for local configuration, diagnostics, replay, and Atlas. Only their transport envelopes differ.

One bounded operation context

Each operation shares captured immutable file buffers and a normalized View index. The next request gets a fresh capture, not a global customer-state cache.

Read-only dependency injection

Read handlers receive a bounded ProjectReader with no writer, credential, shell, or network capability. The real Rust engine remains the decision owner.

Protected generation

Writes require --write. Planning and commit share conflict rules; changed configuration or managed guidance aborts the old plan.

Two independent artifacts

The service and native toolkit are packaged separately and tested without source or network. Local evidence is not a production release or live service guarantee.

Read the unification and dependency-injection guide ↗

HUMANS AND CODING AGENTS

HTML and Markdown. The same status and limits.

The website guides have Markdown equivalents and a machine-readable index. The native candidate also bundles skills and a five-tool read-only stdio MCP surface.

PROGRESSIVE ADOPTION

One workload before a larger rollout.

  1. Start with an explicit contract

    Choose one structured workload. Keep business meaning and external action permissions in your application.

  2. Inspect a candidate locally

    Use an approved native artifact to plan setup and exercise synthetic fixtures in the real Rust engine. Nothing in this website executes it.

  3. Integrate the existing History SDK

    Bind subject and type once, record a result, and preserve the returned generation through exact reads. An authorized endpoint is a separate prerequisite.

  4. Qualify the managed journey

    Review identity, effective permissions, retries, corrections, lifecycle, export, and customer exit before any live production commitment.

ONE WORKLOAD. A CLEAR ACCEPTANCE TEST.

Bring the history your agents depend on.

Discuss your AgentCore workload, data boundary, and the failure cases an evaluation must prove.

Discuss an evaluationSee evaluation scopePrelaunch. No production commitment implied.