Kindgi The AI-native runtime for agents as infrastructure. Get started →

Reference

Integration bindings.

Kindgi integrates with external providers through typed adapter packages. Each provider declares a capability kind — llm-inference, sandbox-exec, embedding, and others — which the runtime router matches to agent-declared requirements under tenant policy and budget.

Router — capability match under tenant policy.

Agents declare requirements. The router picks a satisfying provider under tenant policy and per-run budget.

How it works Provider declares capabilityKind and what it can satisfy. Agent declares needs. Router filters by kind, then by needs, then applies tenant policy and budget. Adapter packages register providers of any kind — the same routing works for models, sandboxes, embeddings, and anything else.
Provider kindStatusPurpose
llm-inferenceLiveLanguage model calls — see Models below
embeddingLiveVector generation — see Embeddings below
sandbox-execLiveCode execution — see Sandbox below
gpu-computeRoadmapGPU-heavy workloads: training, fine-tuning, inference
browser-sessionRoadmapHeadless browser sessions for scraping and interaction
Custom kindsLiveAdapter packages register their own kind strings; the router matches strictly

Models — routed by capability.

Route by declared requirement; enforce tenant provider policy.

ProviderStatusNotes
AnthropicLiveAll Claude models
OpenAI & compatibleLiveOpenAI, Azure OpenAI, self-hosted (vLLM, TGI, Ollama) via OpenAI-compatible endpoint
In-process (dev)LiveDeterministic stub for tests + CI
AWS BedrockSoonAnthropic, Llama, Titan via Bedrock
Google VertexSoonGemini + Anthropic via Vertex
CohereRoadmapCommand R+ family

Sandbox — code-execution isolation.

Subprocess for local dev; hypervisor microVM for production.

SandboxStatusIsolation level
Node subprocessLiveSeparate OS process
Firecracker microVMLiveHypervisor-level VM (same tech as AWS Lambda / Fargate / Fly)
Cloudflare WorkersSoonV8 isolate at edge
gVisorRoadmapKernel-syscall filtering

Auth & identity — SSO, SCIM, tenant claims.

Tenants, users, and agent identity.

ProviderStatusNotes
Better AuthLiveSelf-hostable OSS auth (default)
WorkOSSoonEnterprise SSO + SCIM
OktaSoonSSO
Auth0SoonSSO
Azure AD / EntraSoonMicrosoft SSO
OpenFGA (kernel authz)LiveZanzibar-style access — used by the runtime for tenant + role-based access on every call
CerbosRoadmapAlternative policy engine

Secrets — vaults, KMS, and routing.

Local files, encrypted stores, managed vaults.

ProviderStatusNotes
dotenvLive.env file (dev only)
In-memoryLiveTesting / ephemeral
Postgres (encrypted)LiveServer-side encryption via libsodium
AWS Secrets ManagerLiveNative SDK integration
GCP Secret ManagerLiveNative SDK integration
HashiCorp VaultLiveAny Vault deployment
Secrets routerLiveFan out across multiple providers
Azure Key VaultSoonAzure Key Vault integration
InfisicalRoadmapOSS secrets platform

Embeddings — vector generation for retrieval.

Vectors for retrieval and semantic search.

ProviderStatusNotes
Local (Transformers.js)LiveOn-device / self-hosted, no external API
OpenAI embeddingsSoontext-embedding-3-large / small
Cohere embeddingsSoonMultilingual embed-v3
Voyage AIRoadmapHigh-quality specialty embeddings

Evaluation — judges & checks.

Schema validation and LLM scoring.

JudgeStatusNotes
JSON Schema (Ajv)LiveStructured output validation
LLM-as-judgeLiveOpt-in with explicit cost + budget
Custom TS checksLiveAuthor your own zero-LLM checks
Ragas metricsRoadmapRetrieval-augmented eval metrics

Observability — traces, metrics, errors.

OTel-first emitters with vendor collectors.

ToolStatusNotes
OpenTelemetrySoonTraces + metrics via OTel exporter
LangfuseSoonLLM-native observability
SentrySoonError tracking + performance
DatadogRoadmapAPM + logs
Grafana TempoSoonOSS trace backend via OTel export

Interop — MCP, webhooks, event bus.

Consume external tools; emit runtime events to downstream systems.

ProtocolStatusNotes
MCP clientLiveConsume external MCP tools from agents
MCP serverLiveExpose Kindgi tools as MCP
WebhooksSoonHTTP callbacks on run events
Event bus (external)RoadmapKafka / NATS export for downstream consumers
A2A protocolRoadmapGoogle's Agent-to-Agent protocol

Not listed?

Request a binding.

The bindings interface is designed for pluggability. If your database, model, secrets vault, sandbox, or auth system isn't listed, tell us — most adapters are a few hundred lines against the interface.