Skip to content

Rust integration

Use the Rust toolchain compatible with the included Cargo.lock and Cargo.toml. Add aiws-sdk as a path dependency pointing to crates/aiws in the source download, or unpack the supplied .crate file and point to that directory. Add serde_json when constructing JSON-backed records. This release is not published to crates.io.

Execute an adapter through the trusted coordinator · Executable local adapter demonstration; fixed demo identity and fixture evidence

import { readFileSync, writeFileSync, mkdtempSync } from 'node:fs';
import { tmpdir } from 'node:os';
import { join } from 'node:path';
import { parseContract, parseCommand, canonical, assessSuccess } from '@aiws/sdk';
import { SqliteStore } from '@aiws/sdk/sqlite';
import { Coordinator, type EffectAdapter } from '@aiws/sdk/runtime';
// A local demonstration. Replace this fixed demo identity with authenticated policy.
const demo = JSON.parse(readFileSync('examples/review.json', 'utf8'));
const directory = mkdtempSync(join(tmpdir(), 'aiws-review-'));
const store = new SqliteStore(join(directory, 'mission.db'), parseContract(canonical(demo.contract)));
const coordinator = new Coordinator(store, async () => ({ allowed: true, policy: 'ALLOW', mandatoryChecksOk: true,context:{actor:"demo:operator",policyRevision:"policy:1",decisionClass:"DETERMINISTIC"} }), () => '10');
const adapter: EffectAdapter = {
async execute(operation) { writeFileSync(join(directory, 'review.txt'), canonical(operation.action.payload), { flag: 'wx' }); return { effect: 'CONFIRMED_APPLIED', actualCost: '3' }; },
async reconcile(operation) { try {
return { effect: readFileSync(join(directory, 'review.txt'), 'utf8') === canonical(operation.action.payload) ? 'CONFIRMED_APPLIED' : 'UNKNOWN', actualCost: '3' };
}
catch {
return { effect: 'UNKNOWN', actualCost: '0' };
} }
};
try {
for (const raw of demo.commands) {
const command = parseCommand(canonical(raw));
if (command.type === 'dispatch')
await coordinator.dispatch(command.attemptId, adapter, command.nodeId);
else
await coordinator.apply(command);
}
console.log(JSON.stringify({ directory, ...assessSuccess(store.snapshot(), 'r') }));
writeFileSync(join(directory, 'audit.json'), store.exportAudit());
}
finally {
store.close();
}

The full program uses a local adapter, fixed trusted demo identity and fixture evidence. Replace those three boundaries with real identity, a scoped adapter and measured validation evidence before using this pattern in production. The tab set includes equivalent Rust, TypeScript and Python implementations.

The current repository source adds a small protocol-correlation helper after the previously built SDK 0.3.0 binary baseline. It records the exact Praxis binding revision and remote identity alongside the AIWS work/run/operation/attempt identity. It does not implement MCP, A2A or AG-UI transport behavior and always validates authoritative: false.

Correlate governed work with a protocol binding · Executable source-only SDK correlation example; no protocol client or authority is created

import assert from 'node:assert/strict';
import {createMission,reduce,protocolCorrelation,type Contract} from '@aiws/sdk';
const contract:Contract={id:'contract:protocol',missionId:'mission:protocol',aiwsEdition:'0.4',profile:'finite-v1',budget:'20',deadline:'1000',criteria:['remote-result-reviewed'],actions:['remote.invoke'],resources:['protocol:mcp'],requiresApproval:false,maxAttempts:'2',maxAuthorizationAgeMs:'100',features:[]};
let state=createMission(contract);
state=reduce(state,{type:'startRun',runId:'run:1'},'10');
state=reduce(state,{type:'grant',grant:{id:'grant:1',subject:'agent:1',profile:'finite-v1',actions:['remote.invoke'],resources:['protocol:mcp'],notBefore:'0',expiresAt:'1000',limit:'20',canDelegate:false,depth:'0'}},'10');
state=reduce(state,{type:'admit',runId:'run:1',operationId:'operation:1',attemptId:'attempt:1',grantId:'grant:1',subject:'agent:1',action:{capability:'remote.invoke',resource:'protocol:mcp',payload:{tool:'echo'},preconditions:{}},amount:'5',authorizationCheckedAt:'10',policy:'ALLOW',mandatoryChecksOk:true},'10');
const correlation=protocolCorrelation(
{bindingId:'mcp:official-v2',bindingRevision:'1',protocol:'MCP',protocolVersion:'2026-07-28',manifestDigest:'a'.repeat(64),capabilityDigest:'b'.repeat(64)},
{workOrderId:'mission:protocol',runId:'run:1',taskId:null,operationId:'operation:1',attemptId:'attempt:1',remoteIdentityRef:'mcp:praxis-m9-fixture@1.0.0',remoteOperationId:null}
);
assert.equal(correlation.operation.operationId,'operation:1');
assert.equal(correlation.authoritative,false);
assert.equal(state.operations['operation:1'].runId,'run:1');
console.log('PASS: protocol-correlation');

Use official protocol SDKs and the Praxis adapters for wire behavior. Use this helper only for portable correlation in application code, evidence indexes or integration metadata.

Checked record constructors return Result and enforce the shared schema. Contract::parse and Command::parse preserve strict JSON ingress checks; from_value is suitable for already-decoded trusted values. Inspect snapshots with as_value(); do not circumvent the record constructors by manipulating internal state.

Implement runtime::Authorizer, runtime::Clock and runtime::EffectAdapter in your host. The coordinator owns a SqliteStore and its mutable methods serialize work through that object. These APIs are synchronous. In an async server, run blocking database and adapter work in a controlled blocking worker rather than on an executor thread that must stay responsive.

Propagate errors with ? until a boundary can inspect AiwsError.code, preserve state and choose a recovery decision. Do not unwrap external input. Dropping a coordinator does not cancel an already-applied external action. A timeout at the host still requires read-back or human intervention for ambiguous outcomes.

The guide examples form an independent Cargo workspace under examples/guide/rust. Use cargo run –manifest-path examples/guide/rust/Cargo.toml –bin coordinator from the repository root. Cargo builds native Rust; no Node or Python process implements these SDK operations.

Use the API mapping to translate native calls without changing camelCase wire keys. Use observability for exporter configuration and recovery for interrupted effects. All examples are included as individual executable source files under examples/guide/.

The supplied CLI validates contracts and graphs and replays audit records. Its observe projection uses a fixed test timestamp and is not a live monitoring service. Run operationalSummary/operational_summary with a trusted current timestamp in your application instead.