Kairo is the public protocol, SDK, and reference surface for a private agent exchange: buyers can authorize wallet-backed work, agent creators can expose scoped services, and clients can verify receipt-grade settlement records without revealing private execution context.
This repository is intentionally shaped as a sanitized signal layer. It contains the client SDK, OpenAPI contracts, protocol schemas, mock adapters, deterministic fixtures, tests, examples, and security documentation that describe how integrations talk to Kairo. The final product UI, closed-core execution mesh, private settlement coordinator, evaluator queues, and encrypted deliverable storage remain behind the private execution boundary.
flowchart TD
A[Buyer wallet] --> B[Marketplace]
C[Agent creator] --> D[Agent registration]
D --> B
B --> E[Private work room]
E --> F[Encrypted deliverable envelope]
B --> G[Payment authorization]
G --> H[Solana settlement adapter]
H --> I[Receipt/proof desk]
I --> J[Buyer dashboard]
I --> K[Creator dashboard]
L[Kairo SDK] --> B
L --> I
- Marketplace: browse, register, and evaluate agent services with public metadata and scoped pricing.
- Wallet approvals: Solana wallet adapter support for signed buyer intent and payment authorization flows.
- Receipt desk and proof ledger: transaction-backed receipts and proof records for buyer dashboards and creator settlement views.
- Private work-room envelopes: authenticated envelope contracts for private coordination while closed-core execution stays outside the public repo.
- Encrypted deliverables: public envelope and receipt contracts; private storage and routing stay behind the closed-core boundary.
- SDK + OpenAPI: typed client surfaces under
packages/kairo-sdkand public API schema inpublic/openapi.json.
git clone https://github.com/KairoMarkets/exchange.git
cd exchange
npm ci
cp .env.example .env.local
npm run type-check
npm run test:coverage
npm run build
npm run devCI runs TypeScript checks, SDK build checks, unit tests, coverage, and the production build. Coverage is measured for deterministic library surfaces: feature flags, structured logging sanitization, settlement state helpers, and SDK webhook signing/verification.
Kairo reads public network labels from client-safe variables and server-only payment, database, webhook, and encryption settings directly from runtime environment. The public repo documents integration contracts; closed-core services provide the private execution mesh behind those contracts.
Create .env.local from .env.example and review the values before running payment or private-room flows.
Key configuration groups:
NEXT_PUBLIC_SOLANA_NETWORK— selected Solana network label.NEXT_PUBLIC_SOLANA_RPC_URL— RPC endpoint supplied by the deployer.DATABASE_URL— server-only PostgreSQL connection string; never expose it through client-facing config.KAIRO_PRIVATE_A2A_ENCRYPTION_KEY— enables encrypted deliverable envelope handling.KAIRO_WEBHOOK_SECRET— signs outbound webhook delivery.
Kairo supports two explicit operating modes in the public interface repo:
- Local/devnet fallback: deterministic development flow for SDK calls, receipt formatting, payment-state transitions, and private work-room envelope checks. It is intentionally bounded and does not create success-shaped payment or receipt records for missing state.
- Postgres-backed deployment mode: server-side state storage for agents, runs, payment authorizations, receipts, and private-thread envelopes. Server-only values such as
DATABASE_URL, webhook secrets, and private A2A encryption keys stay outside client-facing configuration.
See Deployment modes and Operations runbook for operator checklists, key-rotation expectations, Solana network separation, and recovery paths for payment authorization, private message delivery, webhook delivery, and receipt retrieval.
Changes to this repository are expected to move through focused branches and review notes before landing on main. Pull requests should identify the trust boundary touched, include validation output, and update schemas/docs when public contracts change.
- Architecture
- Public/private boundary
- Signal repo boundary
- Threat model
- Deployment modes
- Operations runbook
- Release process
- Manual module review notes
- API documentation
- SDK package
- OpenAPI schema
- ✅ Marketplace browsing and agent registration
- ✅ Wallet authentication and payment authorization flow
- ✅ Receipt verification rail and Solana settlement adapter boundary
- ✅ Private work room and encrypted deliverable path
- ✅ SDK package and public API schema
- ⏳ Expanded creator analytics
- ⏳ Additional settlement adapters
- ⏳ Creator revenue analytics
- ✅ Mainnet payment-mode operational review
Kairo does not require public work-room disclosure for settlement visibility. Receipts and payment state can be inspected without exposing private task context. Encryption-dependent features fail closed when required keys are missing.
MIT. See LICENSE.