Open-source research alpha · MIT licensed

Give agents a boundary.
Not a bank account.

Parimit lets an AI agent propose a payment intent, applies deterministic policy, routes the exact request for reviewer decision, and produces verifiable evidence—without connecting to a payment rail.

No UPI, bank, PSP, wallet, merchant, debit, settlement, refund, or payment-execution connection exists in this release.

0execution tools
6proposal-safe MCP tools
101alpha.4 automated tests
16/16smoke checks at d9807d3

Agents propose. Deterministic policy constrains. Reviewers decide. Parimit records evidence. Execution stays elsewhere.

A narrow, inspectable workflow

From suggestion to evidence—then stop.

Parimit separates an untrusted proposal plane from a distinct reviewer role. In OIDC mode that role can be bound to an authenticated subject. Approval is evidence, not a payment instruction.

01

Propose

An agent submits a structured amount, currency, opaque payee reference, purpose, expiry, and idempotency key.

02

Constrain

Deterministic rules check limits, payee lists, daily exposure, purpose, expiry, and whether dual approval is required.

03

Decide

One or two distinct reviewer identities approve or reject the exact proposal. Local-demo identities are spoofable labels; OIDC mode verifies authenticated subjects. Agents never receive approval authority.

04

Prove

Parimit issues non-dispatchable receipts and short-lived signed evidence, then appends the decision to a hash-linked audit history.

The architectural boundary

A control plane with a deliberate missing link.

The proposal, policy, decision, and evidence surfaces share one rule: no shipped interface can turn approval into a provider command.

  • Network-free deterministic domain and policy core
  • Separate agent, reviewer, consumer, and administrator roles
  • Exact-intent digests and one-time local evidence consumption
  • Fail-closed audit verification and uncertainty handling
Read the architecture
Parimit architecture: an agent proposes, a separate reviewer decides, Parimit records non-dispatchable evidence, and no route reaches a bank, PSP, or UPI rail.
AIAgentUntrusted
✓ReviewerSeparate role
Parimit boundary
Validate→Policy→Review
Evidence+Audit
◇EvidenceNon-dispatchable
₹Bank / PSP / UPIOut of scope

Available in alpha.4

One boundary, several safe interfaces.

Use Parimit locally as a browser demo, through REST and a role-shaped SDK, or through a deliberately narrow MCP process.

Core

Proposal governance

Structured validation, deterministic policy, one- or two-person review, cancellation, expiry, idempotency, and mock outcomes.

INR minor unitsExact intentIN_DOUBT freeze
Interfaces

REST + SDK

OpenAPI-documented endpoints and dependency-free TypeScript clients shaped for each permitted role.

Open API specification
Agents

Six safe MCP tools

Create, inspect, cancel, evaluate policy, simulate mock outcomes, and read audit history—never approve or execute.

Inspect the MCP surface
Identity

OIDC / Keycloak pilot

Signature, issuer, audience, lifetime, algorithm, and fail-closed role validation in a local TLS pilot profile.

View local pilot
Evidence

Signed and inspectable

HMAC receipts, audience-bound Ed25519 envelopes, JWKS verification, one-time local consumption, and hash-linked audit.

Read the envelope spec
Compatibility

AiNxt sidecar

A source-review-anchored adapter turns fixed synthetic drafts into Parimit simulations or proposals. No native connector or payment authority.

Review the adapter

Evidence, not adjectives

What the public evidence actually proves.

The 101 automated tests are current for alpha.4. The 16-check AiNxt smoke is a separately scoped prior-commit record. Neither establishes payment connectivity, certification, or production readiness.

95

Core tests

Policy, identity, evidence, HTTP, MCP, adapter, storage contract, audit, and boundary behavior.

Passing in alpha.4
6

SDK tests

Role-shaped capability separation, request encoding, direct JWKS use, and structured errors.

Passing in alpha.4
16/16

AiNxt smoke checks

At Parimit commit d9807d3: one synthetic coffee proposal, exact replay, policy-denied mobility fixture, and loopback-only components.

Prior-commit public evidence
Published result · d9807d3

The recorded allowed scenario stopped at AWAITING_APPROVAL.

Zero approvals were attempted. No interactive human participated. The denied scenario created nothing. Payment-execution capability remained false.

Relationship to India’s ecosystem

Independent software. Public inspiration. No implied endorsement.

Parimit is independently implemented. Its separation between an AI-facing proposal plane and a payment boundary was informed by publicly available NPCI AiNxt OS material. No AiNxt source code was copied into the initial implementation.

The optional AiNxt adapter is a controlled compatibility study—not an NPCI integration, certification, native tool, AtOM connection, UPI connection, or authorization to access a regulated payment rail.

Inspect source provenance

Honest readiness

Strong research alpha.
Hard no-go for real money.

The next milestones strengthen identity, storage, operations, and external accountability before any regulated integration is even considered.

Read the real-integration gates

Public research alpha

Available now

Proposal governance, safe interfaces, local demo, OIDC pilot profile, evidence, documentation, and public release.

Interactive synthetic pilot

Next gate

Two real people complete reviewer and administrator device login, inspect exact fictional proposals, decide, and retain a redacted report.

Production-grade control plane

Not built

Live PostgreSQL parity, managed keys, distributed replay defense, monitoring, rate limits, backup, disaster recovery, and independent security work.

×

Regulated payment integration

Not authorized

A separate deterministic executor, licensed bank or PSP relationship, webhooks, reconciliation, certification, legal review, and written approvals would all be required.

For builders and reviewers

Clone it. Inspect it. Keep the boundary intact.

Parimit runs locally on Node.js 24 with no third-party runtime dependencies. The browser demo stores demo state locally; use only fictional data.

Terminal
# Run the proposal-only local demo
git clone https://github.com/cad07/parimit.git
cd parimit
npm start

# Verify tests, SDK and boundary checks
npm run check

Plain answers

Before you use Parimit.

Can Parimit make a UPI or bank payment?

No. The alpha has no bank, PSP, UPI, wallet, merchant, or payment-provider connector. The simulator creates labelled fictional outcomes only.

Does reviewer approval authorize execution?

No. Approval records that configured policy and reviewer-decision conditions were met; only OIDC mode authenticates the reviewer subject. The evidence is deliberately non-dispatchable and signs explicit false values for execution authority and money movement.

Is this an NPCI product or endorsement?

No. Parimit is an independent open-source project. Public AiNxt material informed part of the safety boundary, and a source-reviewed compatibility sidecar exists, but there is no NPCI endorsement, certification, or rail access.

Is it production-ready?

No. It is suitable for research, code review, local demonstrations, and a controlled synthetic pilot after interactive acceptance. Real-money production remains a hard no-go.

Bounded by design

Explore the proposal boundary.

Read the code, reproduce the checks, and help strengthen the line between agent intent and real-world value movement.