What Promptise is
The framework for agentic intelligence.
Promptise gives you everything an agentic system needs, in one place and working together from the first line: agents that think, safe ways for them to act in your systems, and a harness that keeps them running and accountable. You decide what your agent should do; Promptise takes care of everything around it.
Start with one agent on your laptop and grow it into a fleet running real work, with the same framework and the same way of building all the way through. No rewrite in between, and nothing to stitch together yourself.
| Layer | What it does for you | |---|---| | Agent · it thinks | Agents that work through a task step by step, check their own work and get it right. | | Interface · it acts | Safe access to your tools, your data and the systems you already run. | | Harness · it operates | Keeps your agents running around the clock, within budget, and accountable for everything they do. |
Get started in 30 seconds
pip install promptise
import asyncio
from promptise import build_agent, PromptiseSecurityScanner, SemanticCache
from promptise.config import HTTPServerSpec
from promptise.memory import ChromaProvider
async def main():
agent = await build_agent(
model="openai:gpt-5-mini",
servers={
"tools": HTTPServerSpec(url="http://localhost:8000/mcp"),
},
instructions="You are a helpful assistant.",
memory=ChromaProvider(persist_directory="./memory"), # remembers across calls
guardrails=PromptiseSecurityScanner.default(), # blocks injection, redacts PII
cache=SemanticCache(), # serves similar queries instantly
observe=True, # traces every step
)
result = await agent.ainvoke({
"messages": [{"role": "user", "content": "What's the status of our pipeline?"}]
})
print(result["messages"][-1].content)
await agent.shutdown()
asyncio.run(main())
One call. The agent discovers its tools on the MCP server by itself; memory, guardrails, cache and tracing are one argument each, and the ones you leave out cost nothing. Vector memory and the ML guardrails need the extras: pip install "promptise[all]".
Any model, one string. openai:gpt-5-mini · anthropic:claude-sonnet-4-5 · azure:chat-prod · gemini:gemini-2.5-pro · bedrock:… · ollama:llama3.1. The same string works in build_agent(), .superagent files and every CLI command, and promptise models check tells you exactly what a provider still needs. → Model setup
One request, through the whole system
A customer writes in at three in the morning. The runtime wakes the agent, its identity is established, the input is checked, it gathers context, plans, calls a tool through MCP, a person approves the refund, it checks its own work, answers, and every step lands in the audit trail.
Walk through all fourteen steps, with every module linked →
Already have an API? MCPcast it.
promptise mcpcast openapi.yaml --profile standard --auth env-token
MCPcast reads an OpenAPI or Swagger document and writes a real, reviewed MCP server: a small set of tools an agent can actually use, chosen and described for agents. Reads by default; writes only when you ask, and every one of them approval-gated on the server, so a person signs off before anything changes, whichever MCP client calls it.
What comes out is a project, not a script: an installable package, a launcher, a generated test suite, pyproject.toml, a Dockerfile and a README, all regenerated from mcpcast.plan.yaml, the one file you edit. --eval grades the result A to F with a real agent before you ship, and plain promptise mcpcast opens a guided setup in the terminal. Above: the real output for the Swagger Petstore spec. → MCPcast, end to end
Built for governance and structure
For people and teams who need their agentic systems to be accountable: who did what, on whose behalf, within which limits. These are part of the framework, not something you add later.
- Multi-tenant, by construction. Tag a request with a tenant, and every place data lives — memory, cache, conversations, rate limits, audit — stays separated per tenant. Two tenants who both have a user named
alicecan never see each other's data. It's a structural rule, not a filter you have to remember on every query. → Multi-Tenant Platform guide
- Human approval, enforced on the server. Mark a tool as needing sign-off and the approval is required no matter which app calls it — including one you didn't write. Denies on timeout, rejects self-approval, records who approved what. → Approval Gates
- A real identity for each agent. Agents authenticate as themselves to the APIs they call, backed by Microsoft Entra ID, AWS, Google Cloud, SPIFFE, or plain OIDC — so you can retire the shared API key, and every action traces to the person it acted for, even across agents calling agents. → Agent Identity
- Audit you can hand to a reviewer. Every action is written to a tamper-evident chain, tied to the tenant and the user. Delete one tenant's data with a single call when they ask. → Auth & Security
- Runs offline. The security models, embeddings, and vector store can all run locally — so the whole stack works air-gapped, for on-premises and regulated environments where data can't leave. → Guardrails · Model Setup
Everything Promptise ships
Works with what you already run
| Area | Works with |
|---|---|
| Models | OpenAI · Anthropic · Azure OpenAI & AI Foundry · Gemini & Vertex AI · Bedrock · Mistral · Groq · Ollama · Hugging Face · any LangChain chat model · FallbackChain for failover → Model setup |
| Memory & vectors | ChromaDB · Mem0 · Sentence Transformers · local embeddings for air-gapped installs → Memory |
| Conversations | PostgreSQL · Redis · SQLite · in-memory, with session ownership enforced → Conversations |
| Identity & auth | Microsoft Entra ID · AWS IAM · Google Cloud · SPIFFE / SPIRE · OIDC · JWT · OAuth 2.0 → Agent Identity |
| Observability | OpenTelemetry · Prometheus · Slack · PagerDuty · webhook · HTML · JSON · console → Observability |
| Sandbox & deploy | Docker · gVisor · seccomp · capability dropping · Kubernetes health probes → Sandbox |
| Protocols | Model Context Protocol over stdio, streamable HTTP and SSE · OpenAPI · HMAC-chained audit logs |
Contributing · Security · Changelog · License: Apache 2.0
Built by Promptise · questions and ideas in Discussions · bugs in Issues
Formerly DeepMCPAgent, a public preview of one part of this framework (MCP-native agent tooling).