SeenRelay
Кооперативная инфраструктура свежести для ИИ-агентов. ПРОВЕРЯЙТЕ недавние наблюдения, подкреплённые источниками, перед повторной валидацией; НАБЛЮДАЙТЕ за тем, с чем агент столкнулся самостоятельно.
Документация
SeenRelay
Help agents decide when a known external state really needs fresh authoritative validation.
SeenRelay sits at the revalidation decision boundary. Keep the state your application already knows, prefer local/private and source-native controls first, consult compatible recent shared observations only when useful, and fall through to the authoritative source whenever evidence or policy is insufficient. Start with a free shadow audit while every authoritative validation remains enabled. Keep SeenRelay only where the result is USE; accept DO NOT USE or INSUFFICIENT EVIDENCE everywhere else.
Currently free · no account · no SeenRelay API key required.
SeenRelay itself requires no account or API key. A third-party client, directory, gateway, or assistant may require its own account to use that third-party service; that is not a SeenRelay access requirement. The canonical direct MCP endpoint is https://seenrelay.com/mcp.
What SeenRelay is deciding
SeenRelay is designed around one question: “I already know X — do I need to pay to validate X again now?”
CHECK is not a lookup for somebody else's raw result. The caller supplies the known value, deterministic source-backed fact identity and its own freshness window. SeenRelay reports compatible recent evidence; the caller keeps authority over whether to validate again.
For a small public set of source-backed facts, use the canonical starter descriptors at https://seenrelay.com/starter-facts.json. They publish identity metadata only — no observed values, no recommended TTL and no reuse authorization. Full decision-layer rationale: docs/DECISION_LAYER.md.
Fastest start: give the audit to your coding agent
Claude Code can install SeenRelay persistently from this repository's validated self-hosted marketplace:
claude plugin marketplace add ovladon/seenrelay
claude plugin install --scope user seenrelay@seenrelay
This direct-install path is repository-hosted and does not imply Anthropic marketplace approval. It does not automatically attach the hosted MCP endpoint or enable reuse.
Other Agent Skills clients can use the canonical domain:
npx skills add https://seenrelay.com --skill seenrelay --yes
Then ask it:
Run a SeenRelay shadow audit on this project. Find repeated expensive read-only validations, preserve every authoritative call, measure stronger local/source/provider-native controls first, do not enable reuse, and return USE / DO NOT USE / INSUFFICIENT EVIDENCE for each measured workload.
Or use the developer paths below. Full audit method: docs/SHADOW_AUDIT.md.
Install: npm install seenrelay · pip install seenrelay · client v0.2.23 · currently free · no account/API key.
Zero-code local prescreen
Before changing application code, ask whether the repository even contains a plausible recurring expensive read-only validation path:
npx seenrelay scan
The scan is local-only: it does not contact SeenRelay, upload source code or modify the project. It reports only pre-evidentiary states such as CANDIDATE_FOR_SHADOW_MEASUREMENT, NATIVE_CONTROL_FIRST, NEEDS_RUNTIME_EVIDENCE and NO_ELIGIBLE_CANDIDATE_FOUND. Static analysis cannot return USE or authorize reuse.
Free shadow audit: measure without changing application behavior
Ambient wraps an existing MCP-style client in local shadow mode. The authoritative call still runs; SeenRelay measures exact repetition and produces a local report.
JavaScript / TypeScript:
npm install seenrelay
import { ambientMcpClient } from 'seenrelay/ambient';
const client = ambientMcpClient(rawMcpClient);
// use client.callTool(...) normally
console.log(client.seenRelayAmbient.getReport());
Python:
pip install seenrelay
from seenrelay_ambient import ambient_mcp_client
client = ambient_mcp_client(raw_mcp_client)
# await client.call_tool(...) normally
print(client.get_report())
Run the existing workload and inspect the report before enabling any bounded reuse. Shared CHECK remains optional and off by default in Zero-State.
SeenRelay is a provider-independent reuse layer for repeated read-only validation. It has exactly two hosted domain operations: CHECK and OBSERVE, and reports recent observations rather than universal truth.
Current JavaScript/TypeScript and Python clients include multi-signal shared-evidence assurance helpers, deterministic Fact Coordinate Kit v1 and provider-independent Zero-State. Python Zero-State supports explicit read-only in-flight/local reuse, caller-owned private L1 and source-native conditional validation before authoritative fallback. The classic Python API and Python Ambient adapters remain shadow-first by default. Shared evidence is explicit caller policy, does not prove truth or independent real-world actors, and MCP/OpenAPI coordinates are local repetition keys unless a stable source-native locator supports a shared fact descriptor. Provider-specific adapters are optional.
What it can avoid
Even with no shared observation:
- simultaneous identical eligible calls can be coalesced in-process;
- completed read-only results can be reused only inside an explicit caller-defined freshness window;
- optional encrypted caller-owned L1 storage can reuse values across workers or restarts;
- ETag / Last-Modified can support source-native conditional confirmation without a shared CHECK;
- shared CHECK is optional in Zero-State and is not placed on the hot path merely because SeenRelay is installed;
- after a genuinely fresh independent validation, OBSERVE can add evidence that may help later callers.
Access is currently free and requires no account or API key.
Start here
- Decision layer:
docs/DECISION_LAYER.md - Canonical starter facts:
https://seenrelay.com/starter-facts.json - Free shadow audit:
docs/SHADOW_AUDIT.md - Claude Code persistent install:
claude plugin marketplace add ovladon/seenrelaythenclaude plugin install --scope user seenrelay@seenrelay - Other coding-agent install:
npx skills add https://seenrelay.com --skill seenrelay --yes - Public install:
npm install seenrelayorpip install seenrelay - JavaScript / TypeScript Zero-State:
clients/typescript/README.md - Fleet economics:
https://seenrelay.com/economics - Client overview:
clients/README.md - Integration choices and MCP setup:
docs/CLIENTS.md - Quickstart:
docs/QUICKSTART.md - Protocol contract:
docs/PROTOCOL.md - Web quickstart:
https://seenrelay.com/quickstart - Web client integrations:
https://seenrelay.com/clients - MCP endpoint:
https://seenrelay.com/mcp - Official MCP Registry:
io.github.ovladon/seenrelay - OpenAPI:
https://seenrelay.com/openapi.json - Machine descriptor:
https://seenrelay.com/service.json - Machine-oriented index:
https://seenrelay.com/llms.txt
How it works
For eligible JavaScript/TypeScript Zero-State calls, the preferred order is:
- exact in-process reuse / coalescing when safe;
- optional caller-owned private reuse;
- source-native conditional confirmation when available;
- optional shared SeenRelay CHECK when configured and useful;
- the application's original validation as fallback;
- OBSERVE only after a fresh independent validation that is eligible for contribution.
For direct REST/MCP or the classic wrapper, CHECK and OBSERVE remain available exactly as before.
Possible CHECK statuses are SAME_OBSERVED, CHANGED_OBSERVED, CONTESTED, STALE, and UNKNOWN.
SAME_OBSERVED means the same value was recently observed for the same deterministic fact identity. It is not a truth verdict. The consuming agent decides whether the evidence is sufficient for its own policy.
JavaScript / TypeScript Zero-State
import { SeenRelayZeroState } from 'seenrelay/zero-state';
const edge = new SeenRelayZeroState({
localMaxAgeMs: 30_000
});
const result = await edge.guard({
coordinate: {
tool: 'catalog.read',
arguments: { id: 42 }
},
validate: async () => expensiveRead()
});
console.log(result.value);
The default completed-result freshness window is 0. SeenRelay does not invent a TTL for arbitrary calls. Mutation/destructive operations must not be suppressed; generic core does not infer read-only safety from tool names, descriptions or untrusted annotations.
For MCP clients, seenrelay/mcp-auto can bind once around explicitly allowlisted callTool() operations. Unlisted tools pass through unchanged.
Classic shadow-first path
The original JavaScript/TypeScript and Python APIs remain available. Without an explicit reuse policy they CHECK, keep the original validation, and OBSERVE the independently obtained result best-effort.
const relay = new SeenRelayClient();
const validatePrice = relay.protectValidation({
fact,
validate: ({ conditionalHeaders }) => existingValidation(conditionalHeaders)
});
const value = await validatePrice(knownValue);
Python exposes the equivalent protect_validation(...) path. Use Shadow Proof when you specifically want to measure public CHECK evidence before enabling classic bounded reuse.
Source-native revalidation
Source-native validators are preferable to guessing freshness. When a retained response carries a safe ETag or Last-Modified validator, a later eligible validation can try If-None-Match or If-Modified-Since. A 304 Not Modified response is confirmation from the source, not from SeenRelay.
The classic CHECK/OBSERVE path can also carry observer-supplied ETag / Last-Modified metadata as an explicitly unverified conditional-request hint. The caller still decides whether source confirmation is required.
Optional private L1
JavaScript/TypeScript Zero-State can use a caller-supplied private store plus codec for reuse across workers or restarts. SeenRelay provides an AES-256-GCM codec helper; the caller owns the key, storage and namespace.
Private values are not sent to the public SeenRelay service merely because private L1 is enabled. Store or codec failure fails open into the application's normal validation path.
Fact identity
SeenRelay uses the versioned seenrelay-fact-v3 identity contract. Identity precedence is:
- stable source-native locator (
json_pointer,element_id,source_key); - canonical machine predicate when no stable locator exists.
Human-readable subject text and mutable observed content do not enter the fact key. Source URLs are canonicalized deterministically without browsing. Credential- or signature-bearing source URLs are rejected before stateful admission.
See docs/PROTOCOL.md for the complete contract.
Observer provenance
OBSERVE supports optional transport-independent ed25519-v1 proof-of-possession. A valid proof establishes key possession, continuity, and payload integrity. It does not establish legal identity, independent real-world actor identity, or truth.
An intermediary provider-cache hit is not re-labeled as a new independent OBSERVE merely because a different caller received it.
Access and contribution
SeenRelay issues signed ephemeral operational leases without account creation. CHECK and OBSERVE are currently free to use. Contribution credit is based on later qualifying reuse rather than raw submission volume.
Hive classes describe operational contribution only; they are not identity or truth scores.
Public interfaces
The canonical domain is seenrelay.com.
- Browser
Accept: text/htmlat/receives the public landing page. - Generic/API requests to
/receive the machine descriptor. /service.jsonexposes the explicit machine descriptor./public-stats.jsonexposes privacy-safe aggregate activity./openapi.jsonexposes the REST contract./mcpexposes MCP2026-07-28./quickstartand/clientsprovide integration instructions.
Product boundary
SeenRelay itself does not browse or search fact sources, perform on-demand external verification, call an LLM to decide truth, or expose a shared general-agent memory. UNKNOWN simply means no sufficiently recent reusable shared observation is available.
Client-side adapters can use source-native validation or integrate with existing providers, but provider adapters are optional and cannot become dependencies of the provider-independent core.
Architecture
- Vercel managed deployment
- Neon Postgres state store
- Hono + TypeScript / Node 22
- REST/OpenAPI
- MCP
2026-07-28through the official v2 server SDK - provider-independent JavaScript/TypeScript Zero-State client plus classic JavaScript/TypeScript and Python wrappers
- authenticated human-only Control Room for runtime operations and incident controls
A2A is monitored but is not advertised as an implemented product interface.
Verification
npm run check performs TypeScript checks, product guardrails, production dependency auditing, structural tests, and runtime tests. Package Validation clean-installs built npm/PyPI artifacts. The Preview Release Gate additionally exercises REST, MCP, fact identity, security boundaries, runtime controls, and reuse accounting against the required Preview runtime commit, accepting a later serving SHA only when every intervening commit is outside the Vercel runtime boundary.
Builds use the committed lockfile and npm ci.
Maintenance
Dependabot and Standards Watch prepare isolated maintenance work. Production changes remain subject to compatibility, security, CI, and Preview verification gates.
Bootstrap
npm ci
npm run check
# DATABASE_ADMIN_URL must be set only for this migration command
npm run db:migrate
Deployment details are in docs/DEPLOYMENT.md.