DevMind
About
Runtime governance for autonomous AI agents. Deterministic policy engine that intercepts and evaluates every action before execution — no LLM in the decision path, sub-50ms response.
Explore
DevMind runs as a remote MCP server. Any MCP-compatible agent — Claude Desktop, Cursor, Codex, OpenCode, or any client supporting the Model Context Protocol — can connect directly over HTTP, with no local Python setup.
Live MCP endpoint:https://devmind-mcp.onrender.com/mcpHealth check (no auth required):https://devmind-mcp.onrender.com/healthProtected Resource Metadata (RFC 9728):https://devmind-mcp.onrender.com/.well-known/oauth-protected-resource
devmind-mcp is a spec-compliantOAuth 2.1 Resource Server. Every credential is scoped to a single agent/organdbound to a specific resource server (Resource Indicators, RFC 8707) — a token minted fordevmind-mcpis rejected by the REST API and vice versa, and a token bound to one agent is rejected if used as another. Requests without a valid, correctly-scoped token receive a spec-correct401with aWWW-Authenticateheader pointing back at the Protected Resource Metadata endpoint above, before reaching the governance engine./healthis exempt, so external monitoring (uptime checks, load balancer probes) can verify liveness without credentials.
Getting a token today:there is no self-service interactive login yet (no Authorization Code + PKCE flow) — with a small number of known agent clients, credentials are issued directly viascripts/issue_token.py, backed by Supabase.[Request one by opening an issueand you'll get back a token scoped to your agent and to the MCP resource specifically. A full interactive OAuth flow is planned once third-party self-service distribution opens (see Roadmap).
The control plane that sits between an agent's decision and your production systems.
DevMind intercepts, evaluates, and audits every action an AI agent attempts to take — before it executes. Deterministic policy engine. No LLM in the decision path. Sub-50ms response time.
Live MCP server:devmind-mcp.onrender.com/mcp-- connect Claude Desktop, Claude Code, Cursor, Codex, or any MCP client directly to your agent's runtime.Live REST API:devmind-2cej.onrender.com/health-- for CI/CD pipelines and scripts that aren't MCP clients.210 invariant tests passing · CI green on every push
On April 25, 2026, a Cursor AI agent deleted PocketOS's entire production database — including every backup — in nine seconds. A single API call. No confirmation prompt. No governance layer. Just an agent with a token that had far more permissions than the task required.
Agents are becoming capable enough to take consequential, irreversible actions autonomously: deploying to production, executing database migrations, modifying infrastructure, rotating secrets. Most organizations have no layer that evaluates those actions before they execute.
Try the exact scenario against the live API:
curl -X POST https://devmind-2cej.onrender.com/evaluate-change \ -H "Content-Type: application/json" \ -H "Authorization: Bearer $DEVMIND_TOKEN" \ -d '{ "agent_id": "cursor-agent", "change_type": "terraform_apply", "surface": "infrastructure", "payload": "production volume destroy", "affects_production": true, "blast_radius": "org" }'
{ "decision": "ESCALATE", "risk_score": 15.0, "why": [ "Signal matched: prod_resource_name (+15)", "Blast radius is ORG -> ESCALATE (irrecoverable scope, no override)" ], "escalation_required": true }
No agent touched Railway. The decision returned before the call was ever made.
Sign in to leave a review
Use Google, GitHub, or an email account so ratings stay tied to real people.
No reviews posted yet.



