Reference
Kindgi integrates with external providers through typed adapter packages. Each provider declares a capability kind — llm-inference, sandbox-exec, embedding, and others — which the runtime router matches to agent-declared requirements under tenant policy and budget.
Agents declare requirements. The router picks a satisfying provider under tenant policy and per-run budget.
| Provider kind | Status | Purpose |
|---|---|---|
| llm-inference | Live | Language model calls — see Models below |
| embedding | Live | Vector generation — see Embeddings below |
| sandbox-exec | Live | Code execution — see Sandbox below |
| gpu-compute | Roadmap | GPU-heavy workloads: training, fine-tuning, inference |
| browser-session | Roadmap | Headless browser sessions for scraping and interaction |
| Custom kinds | Live | Adapter packages register their own kind strings; the router matches strictly |
Route by declared requirement; enforce tenant provider policy.
| Provider | Status | Notes |
|---|---|---|
| Anthropic | Live | All Claude models |
| OpenAI & compatible | Live | OpenAI, Azure OpenAI, self-hosted (vLLM, TGI, Ollama) via OpenAI-compatible endpoint |
| In-process (dev) | Live | Deterministic stub for tests + CI |
| AWS Bedrock | Soon | Anthropic, Llama, Titan via Bedrock |
| Google Vertex | Soon | Gemini + Anthropic via Vertex |
| Cohere | Roadmap | Command R+ family |
Subprocess for local dev; hypervisor microVM for production.
| Sandbox | Status | Isolation level |
|---|---|---|
| Node subprocess | Live | Separate OS process |
| Firecracker microVM | Live | Hypervisor-level VM (same tech as AWS Lambda / Fargate / Fly) |
| Cloudflare Workers | Soon | V8 isolate at edge |
| gVisor | Roadmap | Kernel-syscall filtering |
Tenants, users, and agent identity.
| Provider | Status | Notes |
|---|---|---|
| Better Auth | Live | Self-hostable OSS auth (default) |
| WorkOS | Soon | Enterprise SSO + SCIM |
| Okta | Soon | SSO |
| Auth0 | Soon | SSO |
| Azure AD / Entra | Soon | Microsoft SSO |
| OpenFGA (kernel authz) | Live | Zanzibar-style access — used by the runtime for tenant + role-based access on every call |
| Cerbos | Roadmap | Alternative policy engine |
Local files, encrypted stores, managed vaults.
| Provider | Status | Notes |
|---|---|---|
| dotenv | Live | .env file (dev only) |
| In-memory | Live | Testing / ephemeral |
| Postgres (encrypted) | Live | Server-side encryption via libsodium |
| AWS Secrets Manager | Live | Native SDK integration |
| GCP Secret Manager | Live | Native SDK integration |
| HashiCorp Vault | Live | Any Vault deployment |
| Secrets router | Live | Fan out across multiple providers |
| Azure Key Vault | Soon | Azure Key Vault integration |
| Infisical | Roadmap | OSS secrets platform |
Vectors for retrieval and semantic search.
| Provider | Status | Notes |
|---|---|---|
| Local (Transformers.js) | Live | On-device / self-hosted, no external API |
| OpenAI embeddings | Soon | text-embedding-3-large / small |
| Cohere embeddings | Soon | Multilingual embed-v3 |
| Voyage AI | Roadmap | High-quality specialty embeddings |
Schema validation and LLM scoring.
| Judge | Status | Notes |
|---|---|---|
| JSON Schema (Ajv) | Live | Structured output validation |
| LLM-as-judge | Live | Opt-in with explicit cost + budget |
| Custom TS checks | Live | Author your own zero-LLM checks |
| Ragas metrics | Roadmap | Retrieval-augmented eval metrics |
OTel-first emitters with vendor collectors.
| Tool | Status | Notes |
|---|---|---|
| OpenTelemetry | Soon | Traces + metrics via OTel exporter |
| Langfuse | Soon | LLM-native observability |
| Sentry | Soon | Error tracking + performance |
| Datadog | Roadmap | APM + logs |
| Grafana Tempo | Soon | OSS trace backend via OTel export |
Consume external tools; emit runtime events to downstream systems.
| Protocol | Status | Notes |
|---|---|---|
| MCP client | Live | Consume external MCP tools from agents |
| MCP server | Live | Expose Kindgi tools as MCP |
| Webhooks | Soon | HTTP callbacks on run events |
| Event bus (external) | Roadmap | Kafka / NATS export for downstream consumers |
| A2A protocol | Roadmap | Google's Agent-to-Agent protocol |
Not listed?
The bindings interface is designed for pluggability. If your database, model, secrets vault, sandbox, or auth system isn't listed, tell us — most adapters are a few hundred lines against the interface.