Ujex

Built for accountable production

Give every agent a mandate you can verify.

Ujex combines portable agent identity, scoped credentials, human approval, signed evidence, policy, secrets, metering, and an inbox behind SDKs and a native MCP server.

Repository-backed product facts · reviewed 26 August 2026

Architecture and value

Authorize the exact action, keep credentials out of the model context, and leave an evidence bundle another system can verify offline.

Agent Passport

A signed passport binds agent, device, delegation claims, mailbox, and latest audit anchor.

Mandate and consent plane

Short-lived mandates state action, resource, budget, expiry, and whether human consent is required.

Provenance Ledger

Hash-linked events, signed bundles, manifests, anchors, and trust bundles preserve provenance.

Compare operating models

Expand the matrix. Choose by boundary and workflow, not slogans.

Ujex ↔ Auth0 · official AI-agent and FGA docs reviewed 2026-08-26
Primary jobThis systemAlternative · Auth0
Primary jobAgent passports, scoped mandates, approvals, evidence, inbox, and budgetsHuman, machine, and agent authentication plus fine-grained authorization
Deployment boundaryFirebase reference control plane with replaceable Apache-2.0 SDKsManaged identity and authorization platform; OpenFGA-based FGA
Evidence modelHash-chained audit, signed AAT bundles, manifests, and trust bundlesAuthorization and access logs; verify current retention and export terms
Operator controlMandate expiry, human approval, tool authorization, and estimated-spend checksOAuth/OIDC, RBAC/ReBAC, consent, and policy enforcement
Integration surfacePython, Go, TypeScript, CLI, MCP, REST, signed callbacksSDKs, APIs, Actions, OAuth/OIDC, and FGA APIs

Technical invariants

Scoped authority
Every credential and mandate is least-privilege, expiring, and tenant-scoped.
Server-side secrets
Provider credentials are injected server-side and never placed in prompts or browser storage.
Fail-closed verification
Compliance callbacks and evidence verification reject missing, stale, or invalid signatures.
Portable evidence
Evidence, retention, verification, auditor access, and open-format export are never usage-metered.

Transparent access

Gateway

2,400 SEK / agent / month

Wrap an existing runtime with identity, mandates, countersignature, and evidence.

Full custody

4,800 SEK / agent / month

Add Ujex-provisioned compute, complete trajectories, replay, and memory review.

Regulated

Written quote

Scope residency and regulated-domain mapping in a written engagement.

Current status. Core identity, inbox, approvals, audit, and SDK surfaces are documented as live; consult subsystem status before relying on adjacent capabilities.

Frequently asked questions

What is the safest way to evaluate it?

Start with the architecture, reproduce the documented workflow, and verify the boundary against your own threat model.

Does the comparison include live third-party pricing?

No. Mutable vendor pricing is deliberately excluded. Verify current vendor terms before a purchase decision.

Where are limitations documented?

The status note, architecture page, and engineering articles state the current boundary and failure behaviour.