doax
The catalog of what AI agents may do on your behalf.
The catalog of what AI agents may do on your behalf.
Publish your data and actions as versioned, namespaced resources — the npm model, for AI. One catalog an agent can actually read.
Every access and execution becomes a definitive, non-restorable audit event. Nothing an agent does for you is invisible, and nothing can be edited away.
Every resource declares the authentication tier it demands — and downstream, that demand can only be strengthened, never weakened.
A durable public registry and a one-click private one. Resolve and audit. Two rings — one infinity.
Data sources, actions, execution places, and credential flows are all published, versioned, made visible, verified, tiered, and audited by the same rules.
One collection an agent reads. The source decides what the caller sees — the registry never shapes data.
An effect in an external system, with declared dry-run, idempotency, and a recovery action.
An org-operated machine for work that can't run on the caller's device, with org-held credentials.
How one target system is authenticated — shared, so a caller logs in once.
The doax CLI is the executor: it resolves resources, verifies integrity, runs the authentication tier each resource demands, and records every access in the audit log. Linux or macOS, Node ≥ 20, nothing else.
curl -fsSL https://doax.io/install.sh | bash
doax search slackfind something to usedoax read @doax/slack-channel-history --param channel=C0123456789asks for your Slack token in context, then readsdoax execute @doax/slack-post --param channel=C0123456789 --param text="hello" --dry-runpreview with zero side effects, then drop --dry-run한빛정밀 is a fictional 12-person molding shop. Its shift-end spreadsheet became five registry resources under @demo, and its dashboard is a doax-app: a static page that resolves the resources from the registry, verifies each package's sha-256 digest in the browser, and reads everything through the Fixed Interface. The dashboard leads with the gap — target, state, fault points — not just status.
The live dashboard. It sits behind doax sign-in — enter any email, get a 6-digit code. The sign-in gate is part of the demo: apps are governed surfaces, not public pages.
Three data-sources over the posted shift-end export, a Slack report action, and a tier-2 reorder action an agent can prepare but only a human may execute.
Owner signs in and claims the namespace, the FDE publishes the kit and deploys the app. The customer hosts nothing; every access lands in their audit log.
Query by name, namespace, or what it does. Filter by kind and tier. Results resolve from registry.doax.io when the live search API is available.