zttp agent-compiler

Your AI writes the code. The compiler proves it.

zttp is an agent-compiler: the compiler works as a second agent in your coding session. It checks every draft before it reaches disk, and it fixes the mistakes it knows without another model call.

$ curl -fsSL https://raw.githubusercontent.com/srdjan/zttp/main/install.sh | sh

macOS and Linux, x86-64 and ARM64. Inspect the install script before you run it.

zttp expertone session
$ zttp expert "add auth to the webhook"

[agent]    draft 1: simulating before write
[veto]     draft adds a violation
  error[E0003]: try/catch is not supported in zts
    --> handler.ts:12:5

[compiler] canonicalize and re-simulate: still red
[compiler] typed repair: try/catch -> Result
[compiler] applied with no model call
           edit recorded: compiler-authored

  PROVEN  3/3 declared | 6/7 properties
The compiler rejects the draft, repairs it with no model call, then proves it.

Runs in your browser

Break a proof in your browser.

Change the code or pick a way to break it. The real analyzer runs on this page as WebAssembly and tells you which guarantee broke and on which line. Your code stays in your browser. The fix buttons replay repairs the compiler made in recorded sessions.

Real analyzer Runs locally Nothing uploaded
handler.ts
proof engine idle
More ways to break it
PROVEN 3 of 3 chosen guarantees proven 6 of 7 guarantees hold pre-rendered proof preview
  • +deterministic
  • +read-only
  • +state-isolated
  • +injection-safe
  • +retry-safe
  • +idempotent
  • -fault-covered
declared Proof<> deterministic no_secret_leakage injection_safe

fault-covered requires a proven recovery path.

One write path

Every edit has two authors.

  1. 01 Draft

    The agent proposes a handler.

  2. 02 Prove

    The compiler checks it before it is saved.

  3. 03 Repair

    The compiler fixes known failures itself, with no model call.

  4. 04 Write

    Only proven code is written.

zttp records who wrote each edit: the model or the compiler. For five safety properties, the compiler plans, applies, and checks the fix on its own, and undoes it if the fix breaks something else.

Why zts restricts TypeScript

zts removes the features the compiler cannot fully check, such as classes, async, try/catch, and while loops. Each removal makes one guarantee provable and gives the agent fewer wrong ways to write code.

Read the restriction map
Compare zttp with bolt-on checkers

Agent plus checker: the code is written first and checked afterwards, in full TypeScript.

Compiler plus agent: the compiler only returns error text, and the model retries with no limit.

zttp: the compiler is an agent too. It shares the only write path with the model and writes its own repairs.

New in 0.21

Turn a handler into a tool an agent can call.

A tool route is an HTTP endpoint for model and agent callers. You describe each tool once, and the runtime checks every call on the way in and on the way out.

Checked input and output

Each tool declares a closed JSON schema for what it accepts and what it returns. A bad request gets a 400 before your code runs, and a bad answer becomes a 500 instead of reaching the caller.

Verified callers

Every call carries a signed token. The runtime checks it, gives your handler the caller and tenant, and answers 403 when a request asks for another tenant's data.

Keys your code never sees

Name an API key in zttp.json. The runtime adds it only to requests for the endpoint, methods, and paths you allow, so the handler never holds the value.

Ledgers that stay balanced

Declare that every currency in a ledger sums to zero. zttp checks each posting before it commits and refuses one that breaks the rule, with nothing written.

import { toolCatalog, toolInput } from "zttp:tool";

toolCatalog({
  convert: {
    route: "POST /tools/convert",
    description: "Convert a temperature between Celsius, Fahrenheit, and Kelvin.",
    input: "ConvertInput",
    output: "ConvertOutput",
    maxInputBytes: 128
  }
});

One declaration per tool. examples/tools is a complete project with two tools.

How a tool call is checked

The runtime refuses an input over the byte limit (413) or one the schema rejects (400), verifies the caller's token (401), and checks the tenant field (403), all before the handler runs. Each tool may call only the modules its own route reaches.

Read the tool route guide
What a ledger invariant does not prove

Balance conservation means the balances in each currency always sum to zero. It does not prove correct recipients, authorization, sufficient funds, or correct business amounts.

Read the invariants guide

Current evidence

What is proven today, and what is not.

zttp grades its own claims the same way it grades code, and the grades live in the repository beside the code they describe.

Holds by construction

A rejected draft never reaches disk. The analyzer gives a verdict for every zts program.

Measured

On a fixed set of 19 coding tasks, 14 first drafts from DeepSeek V4 Flash pass the compiler unchanged, and all 19 end proven.

Not measured yet

Whether a small model on your own machine does as well. That test is planned and has not run.

Attested runtime

Ship the proof with the handler.

zttp deploy builds one signed binary. Before it serves a request, the binary checks the proof again with its own independent checker, and it refuses to start if anything inside was changed. Anyone can run zttp verify <url> to check the signature.

  • One self-contained binary
  • Proof checked at startup
  • Signed and publicly verifiable
Open the full claim ledger

The roadmap names each claim, its evidence grade, and the file that owns the measurement.

Recount the claims
Runtime and workflow details

First proof

Prove your first handler.

Install zttp and scaffold an API. Then add a line zts does not allow, such as try/catch, and watch the compiler name the broken guarantee and the line.

$ curl -fsSL https://raw.githubusercontent.com/srdjan/zttp/main/install.sh | sh

macOS and Linux, x86-64 and ARM64. Inspect the install script before you run it.

zttp init api --template api
cd api
zttp dev

zttp expert needs a DeepSeek key, or --provider local and a local MLX server. The compiler, CLI, and browser playground do not.