Skip to content
adeia fence
Sign in
Where this stands

A working thing,
not a finished one

Adeia is source available and self-hosted. You can sign in with GitHub, get a project and a key, and point an agent at it — but the server still runs on your machine and the database is a file next to it. That is the whole distribution model today, and it is stated here rather than discovered after you try to register.

489 tests passing
BSL 1.1 licence
0 payment processors attached
self-hosted distribution
01 — State

Real, and deliberately unfinished

The two lists below are the honest split. Everything on the left runs; everything on the right is a gap someone would hit, so it is named rather than hidden.

Built and working

  • A policy engine that answers allow, hold or deny, and returns the figure that produced the answer
  • A risk classifier that can decide inside a band you open — and never outside it
  • Email approvals with single-use, expiring, hashed tokens
  • An append-only audit log, redacted at write time
  • A dashboard behind GitHub sign-in: every action, in-page approvals, host allowlists, and key issue and rotation
  • A TypeScript SDK — three methods, no hidden retries
  • 489 tests, and full runs against real mail and a real phone

Deliberately not built

  • No payment processor. The adapter seam is empty on purpose — payments are authorised and recorded, nothing settles
  • One approver per deployment, from APPROVER_EMAIL
  • SQLite, so one writer and one machine
  • No rate limiting
  • @adeia/sdk is not published to npm; it ships in the repository as a workspace
  • No hosted instance yet — you run the server yourself
Built for the Lumos Fellows program. Every layer above the adapter is real; the seam below it is the part left open on purpose, because a convincing fake payment processor is worse than an obvious gap.
02 — Licence

The licence, in plain words

Adeia is under the Business Source License 1.1. Read it, run it, change it, use it in production — all fine. The one thing you may not do is offer it to other people as a hosted service.

On 2030-08-15 each release converts to Apache 2.0 and that restriction lifts permanently.

That makes it source available rather than open source in the OSI sense, and it is worth saying so plainly rather than borrowing a word that means something stricter.

Licence
Business Source License 1.1
Additional use grant
Production use, modification, redistribution and non-production use are all permitted
The one restriction
You may not offer Adeia to third parties as a hosted service
Change date
2030-08-15
Change licence
Apache License, Version 2.0
03 — Getting involved

The repository is the channel

There is no inbox behind this project yet, so rather than print an address that bounces: issues and pull requests are where anything actually gets discussed.

Most useful

Run it and say what broke

Clone it, sign in, issue a key, point an agent at it, and open an issue when the instructions are wrong or something fails in a way the docs did not predict. It has been run by very few people.

Extend

Attach an adapter

The registry takes any action type, not just payments — sending mail, deleting records, calling a paid API. A second adapter would prove the seam is real rather than theoretical.

Attack

Break the approval flow

Tokens are hashed, single use and expiring, and nobody outside this project has tried to defeat that. A serious attempt would be worth more than a feature.