A typed-decision evaluation client for System One (Jev-class) models. Callers ask choice/score/boolean questions over a JSON state record and get back typed decisions — or a typed fallback when the backend is unreachable. Endpoint differences (official, gateway, custom) are config, not forked code.
src/schemas.ts owns every trust boundary — questions, input, decisions,
results — as arktype schemas. src/index.ts is the sole public entry:
src/schemas.ts— everything data-shaped:State,Description,ChoiceQuestion,ScoreQuestion,NoulQuestion,BooleanQuestion, theQuestionunion,QuestionList,JsonRecord,EndpointConfig,EvaluateConfig,EvaluateInput,Confidence,ProbabilityMap,WireQuestion/WireRequest/WireAnswer/WireResponseBody,Decision,Usage,EvaluateResult,FallbackReason,FallbackResult, plus thetoWireQuestions/toDecisionmapping functions.src/config.ts— quirks-as-data:SystemOneQuirks, theSYSTEM_ONE_DEFAULT_QUIRKS/GATEWAY_QUIRKSendpoint presets, env-var names,DEFAULT_TIMEOUT_MS, andresolveEndpoint.src/client.ts— the module-private fetch POST transport (postEvaluate): one JSON round trip with abort-bounded timeout, Bearer auth, typed errors only.src/evaluate.ts—evaluate(): input validation, credential resolution, strict answer cross-validation, and the fallback mapping.src/adapter.ts—createSystemOneAdapter: an InterchangeProviderAdapterbridge (buildRequest/parseResponse/parseJSONResponse/ extractRetryAfterMs) plus theSYSTEM_ONE_PROVIDERid (corbits-system-one).src/errors.ts— the typed error taxonomy (SystemOneError,SystemOneErrorCode); transport failures carry anInferenceErrorreasonfrom the@intx/inferenceclassifiers.src/telemetry.ts— the telemetry event shapeevaluatepasses to the caller'sonTelemetrysink.src/index.ts— re-exports the public subset of the above.*.test.tsnext to the source they cover (pure units).e2e/harness.test.ts— adapter turn andevaluatetimeout through the@intx/inference-testingharness;e2e/live.test.ts— the real endpoint, gated onTYPESAFE_API_KEY.
- Consume
@intx/inferenceand@intx/typesaspeerDependencies(^0.4.0), pinned0.4.0indevDependenciesfor typecheck — never vendor, neverworkspace:. A host must resolve exactly one copy; a second copy breaksinstanceofchecks against the host's own classes. - Parse every trust boundary (caller
EvaluateInput, every backend response body) with arktype; neveras Tuntrusted input. exactOptionalPropertyTypesis on: omit optional keys, never assignundefinedto one.- No product strings baked in — anything endpoint-specific is a config field the caller supplies.
- Public surface is
src/index.ts's export list only:evaluate, the adapter, the timeout default, errors, telemetry event, and the question, input and result schemas. Wire types,postEvaluate,toWireQuestions,toDecision, tolerances and endpoint quirks are module-private; unit tests for them import the owning submodule. - Tests only for load-bearing risk (schema accept/reject on hostile input, timeout/fallback transitions, wire-format encoding) — not for trivial mapping or "returns what I passed in".
- The wire contract is the live Jev API; the source of truth is
https://docs.typesafe.ai (
api.md,primitives/*).stateisstring | object | array;instructionsandcriteriavalues arestring | object | array(structured forms are legal); answers require their kind's fields (noul,choice/score+probabilities+confidence,legendfor score); the envelope may carryusage.input_tokens/output_tokens.
bun install && bun run check