Skip to main content
This page previously said the gateway and connector-enforcement stages are not invoked by the default server. That was true through commit 4740aee (2026-07-08). As of 651497a (2026-07-11), they run on every request — stages 7-8 in the current numbering below. See The gateway for the current mechanism and its one real caveat: only one connector is registered.
Stage numbering changed on 2026-07-28. Signal/Intent binding (now stage 3) is a new stage, added by the G-24 fix — every later stage’s number shifted up by one from what older captures of this page show. See Security for what this stage closed.

Stage-by-stage status

What actually runs when you call POST /execute today

All eleven stages run, in order, on every request. Stage 8’s connector enforcement is real only for the payments:execute action, the one connector wired into createConnectorRegistry.ts, an action with no matching connector fails closed with “No connector registered for action,” it does not silently skip stages 7-8, see The gateway for the mechanism and Quickstart for a verified live run through the full pipeline. Stage 3 (signal/intent binding) is the one stage that can reject a transaction before stage 4 (policy evaluation) ever runs a single rule — see Security for why that ordering matters.

Fail-closed properties that do hold today

  • A rejected Decision never produces a Signed Execution Authorization, authorization signing happens only after executionGate.enforce() approves (packages/runtime/src/RuntimeEngine.ts, CLAIMS.md 2.12, packages/runtime/test/execution-authorization-wiring.test.ts, “rejected transaction produces no authorization”). It throws rather than returning a rejected result, see Write your first policy.
  • Signing or verifying with the wrong key type (e.g. an Ed25519 key against an ML-DSA-65 provider) fails closed with a named error rather than silently dispatching on the key’s own type (assertKeyType, CLAIMS.md 2.13).
  • The Trust Record’s authorizationId is part of the canonically-hashed content, not attached alongside it, tampering with it changes the recomputed hash (CLAIMS.md 2.11).