Skip to content

Repository files navigation

systemprompt.io

SystemPrompt Core

SystemPrompt Core is the Rust library for a control plane you operate: identity, model access, MCP tool execution, policy and audit, with your domain capabilities compiled alongside them.

Crates.io Docs.rs License: BSL-1.1

Evaluate · API docs · Architecture · Security

Capabilities

Connect supported AI clients to your gateway and expose governed MCP tools. Core binds requests to identity, evaluates access and records decisions and usage in PostgreSQL. You operate the runtime, choose the upstream providers and retain the audit data.

Capability Interface
Identity OAuth2/OIDC, authenticated sessions and access rules for users and resources.
Model gateway Anthropic-compatible /v1/messages, model discovery and configurable upstream routing.
MCP and agents Governed tool access and hosted agents with A2A transport.
Enforcement Scope checks, credential-pattern detection, blocklists and rate limits on governed tool calls.
Audit Correlated request and tool records linking identity, decisions, results and inference usage.
Composition Your routes, providers, tools, jobs and persistence registered through extension contracts.

Governance applies to traffic routed through these surfaces. Client-side tool execution needs the corresponding integration; a model gateway alone cannot govern every action on a laptop.

Extension model

SystemPrompt Core + your extensions + your configuration
                           ↓
                 Your compiled runtime
                           ↓
                      PostgreSQL

Build company-specific behavior on the same extension contract used by Core's own domains. The AI domain, for example, registers its schemas, migrations and dependencies through Extension.

An extension can contribute API routes, model and tool providers, scheduled jobs, configuration validation, schemas, migrations and roles. Gateway request guards let you add application-specific decisions before inference dispatch. The demo's credit extension shows that hook in use.

Registration happens at compile/link time through inventory. At startup, the runtime discovers registrations and validates their dependency graph. See the extension API source for the contract and registration flow.

Compiled extensions are trusted Rust code sharing your process. External MCP servers can run separately. This gives you a compact deployment while keeping process isolation available where the integration needs it.

Use as a library

The workspace publishes a systemprompt facade with feature-gated systemprompt-* crates:

[dependencies]
systemprompt = { version = "0.60", features = ["full"] }
Feature Includes
core (default) Shared traits, models, identifiers and extension contracts.
database PostgreSQL integration.
api HTTP server and application context.
cli Command-line entry point.
full Bundled runtime, domain modules and CLI; Slack and Teams remain opt-in.

Use YAML to configure a deployment and Rust extensions to add behavior. Your host links those extensions and delegates startup to Core; the template entry point is a working example.

Evaluate and build

For a running system with configuration, admin UI and scripted enforcement demos, start with the MIT-licensed evaluation template.

To compile this workspace:

git clone https://github.com/systempromptio/systemprompt-core
cd systemprompt-core
just build-offline

Install Rust through rustup and just. The repository pins its toolchain in rust-toolchain.toml and declares Rust 1.96+ with edition 2024. build-offline uses the committed SQLx query cache without a running database; dependency downloads may still require network access. Runtime deployments require PostgreSQL 18+.

The runtime can operate inside a private network or air gap when models, tools and dependencies are available there. Requests routed to cloud providers leave that perimeter. Tool servers may introduce their own runtime dependencies.

Evaluate the boundary

Tool credentials can be supplied to child-process environments without placing them in model context. Credential-pattern scanning provides an additional check on governed arguments; the tool process and its outputs remain trusted parts of the deployment.

Review the evaluation documentation, production deployment guide and template benchmarks against your own requirements. Report vulnerabilities through SECURITY.md.

License

Core is BSL-1.1 source-available, available for evaluation, testing and non-production use under its license terms. Production use requires a commercial license. Each version converts to Apache-2.0 four years after publication.

You control your deployment and extensions; Core's license governs use of the underlying library. Discuss production licensing.

About

AI governance infrastructure for agentic systems. Rust library behind systemprompt.io — MCP, A2A, OAuth2, audit trails, compile-time extensions. Evaluate with systemprompt-template.

Topics

Resources

Security policy

Stars

8 stars

Watchers

0 watching

Forks

Releases

Packages

Used by

Contributors

Languages