Security state is being verified before this view is rendered.
Security state is being verified before this view is rendered.
Developer guidance for connecting real autonomous agents to Nodra’s authority, evidence, containment and recovery control plane.
Use the Nodra SDK workspace to authorize consequential agent actions before execution.
Sign requests server-side and call the protected authorization gateway from Python runtimes.
Integrate any backend capable of SHA-256 and HMAC-SHA256 without depending on a language-specific SDK.
Protect consequential MCP tool calls at the execution boundary instead of relying only on prompt inspection.
Issue, rotate and revoke server-side runtime identities without exposing plaintext secrets in the browser.
Compose an authorization request and generate safe server-side REST, JavaScript, or Python examples without entering secrets.
# Nodra REST uses a signed request. Generate the timestamp, nonce,
# SHA-256 body digest and HMAC-SHA256 signature server-side.
#
# Never paste NODRA_CREDENTIAL into a browser or API client that syncs secrets.
BODY='{"agentId":"finance-agent","resourceId":"stripe","action":"payments.submit","context":{"environment":"production","amount":25000}}'
TIMESTAMP="$(date +%s)"
NONCE="$(python - <<'PY'
import uuid
print(uuid.uuid4())
PY
)"
BODY_SHA="$(printf '%s' "$BODY" | openssl dgst -sha256 -hex | awk '{print $2}')"
CANONICAL="$(printf 'v1\n%s\n%s\n%s' "$TIMESTAMP" "$NONCE" "$BODY_SHA")"
SIGNATURE="$(printf '%s' "$CANONICAL" | openssl dgst -sha256 -hmac "$NODRA_CREDENTIAL" -hex | awk '{print $2}')"
curl --fail-with-body \
--request POST "$NODRA_BASE_URL/api/v1/authorize" \
--header "content-type: application/json" \
--header "x-nodra-credential: $NODRA_CREDENTIAL" \
--header "x-nodra-timestamp: $TIMESTAMP" \
--header "x-nodra-nonce: $NONCE" \
--header "x-nodra-signature: v1=$SIGNATURE" \
--data "$BODY"This explorer generates safe integration code with environment-variable placeholders. It never asks for or stores your Nodra credential in the browser.
Nodra authenticates protected requests, evaluates authority, records ordered evidence and keeps secrets outside browser code.