# Docs - **Getting Started** - [Getting Started](/docs/getting-started): Create an account, get an API key, and make your first Hanzo API call in under five minutes. - [Run Your Org](/docs/run-your-org): From signup to a running brain, team, and bot for your organization — under ten minutes. - [Authentication](/docs/authentication): The one way to authenticate against Hanzo IAM — canonical OIDC endpoints, the @hanzo/iam SDK, and per-framework integration. - [API Keys](/docs/api-keys): Key types, scopes, creation, rotation, and production best practices for Hanzo API keys. - [Organizations](/docs/organizations): Multi-org setup, resource scoping, team management, and white-label login for Hanzo organizations. - **Platform & Services** - Platform: Hanzo Cloud Platform services - [Platform](/docs/services): Hanzo Cloud Platform — 40+ unified services for AI, automation, infrastructure, and operations. - **Core Platform** - Hanzo Cloud: AI Cloud OS — model gateway, knowledge base, and infrastructure management - [Hanzo Cloud](/docs/services/cloud): AI Cloud OS — model gateway, knowledge base, and infrastructure management - The Basics: Core concepts, installation, and getting started - [Core Concepts](/docs/services/cloud/basic/core-concepts): Hanzo Cloud core concepts - [Server Installation](/docs/services/cloud/basic/server-installation): Install and configure Hanzo IAM server - [(Optional) Try with Docker](/docs/services/cloud/basic/try-with-docker): Try Hanzo Cloud with Docker - [(Optional) Try with K8s Helm](/docs/services/cloud/basic/try-with-helm): Learn how to deploy Hanzo Cloud on Kubernetes using Helm - [Container Cloud](/docs/services/cloud/basic/container-cloud) - [Hanzo Cloud Public API](/docs/services/cloud/basic/public-api): Hanzo Cloud Public API - [Hanzo IAM-SSO](/docs/services/cloud/basic/iam-sso): Setup Hanzo IAM for cloud - [System Info](/docs/services/cloud/basic/system-info): Monitor system resources and performance - Beginner Guide: Step-by-step guides for getting started with Hanzo Cloud - [Add an AI Model Provider](/docs/services/cloud/basic/beginner-guide/add-a-model-provider): Learn how to add a model provider to enhance Hanzo Cloud functionality. - [Add an Embedding Provider](/docs/services/cloud/basic/beginner-guide/add-an-embedding-provider): Explore how to integrate an embedding provider with Hanzo Cloud. - [Add a Storage Provider](/docs/services/cloud/basic/beginner-guide/add-a-storage-provider): Discover how to integrate a storage provider with Hanzo Cloud. - [Add a Store](/docs/services/cloud/basic/beginner-guide/add-a-store): Learn how to add a store to your Hanzo Cloud knowledge base system. - [Add a Speech-to-Text Provider](/docs/services/cloud/basic/beginner-guide/add-a-speech-to-text-provider): Learn how to add a speech-to-text provider to enhance Hanzo Cloud functionality. - [Add a Text-to-Speech Model Provider](/docs/services/cloud/basic/beginner-guide/add-a-text-to-speech-provider): Learn how to add a text-to-speech provider to enhance Hanzo Cloud functionality. - [Chats with AI](/docs/services/cloud/basic/beginner-guide/chats-with-ai): Implement AI chat functionality in your Hanzo Cloud knowledge base system. - Providers: Model, storage, embedding, and infrastructure providers - [Overview](/docs/services/cloud/providers): Providers Overview - Model Providers: AI model provider configuration - [Model Providers](/docs/services/cloud/providers/model-providers/index): AI model providers for Hanzo Cloud - [Local Model Provider](/docs/services/cloud/providers/model-providers/local-model-provider): Configure local and custom model providers with OpenAI-compatible APIs - [Embedding Providers](/docs/services/cloud/providers/embedding-providers) - [Storage Providers](/docs/services/cloud/providers/storage-providers) - [Speech-to-Text Providers](/docs/services/cloud/providers/speech-to-text-providers) - [Text-to-Speech Providers](/docs/services/cloud/providers/text-to-speech-providers) - [Bot Providers](/docs/services/cloud/providers/bot-providers) - Blockchain: Blockchain provider configuration - [BlockChain Providers](/docs/services/cloud/providers/blockchain): BlockChain Overview - [Ethereum Configuration](/docs/services/cloud/providers/blockchain/ethereum-configuration) - [Chainmaker Configuration](/docs/services/cloud/providers/blockchain/chainmaker-configuration) - Public Cloud: Public cloud provider configuration - [Public Cloud Providers](/docs/services/cloud/providers/public-cloud): Public Cloud Overview - [Alibaba Cloud Configuration](/docs/services/cloud/providers/public-cloud/alibaba-cloud-configuration): Configure Alibaba Cloud asset scanning - Private Cloud: Self-hosted cloud provider configuration - [Private Cloud Providers](/docs/services/cloud/providers/private-cloud): Private Cloud Overview - [Kubernetes Configuration](/docs/services/cloud/providers/private-cloud/kubernetes-configuration) - Scan Providers: Security and network scanning providers - [Scan Providers](/docs/services/cloud/providers/scan-providers): Network and security scanning providers - [Nmap Scan Provider](/docs/services/cloud/providers/scan-providers/nmap-scan-provider): Network discovery and security auditing with Nmap - [Nuclei Scan Provider](/docs/services/cloud/providers/scan-providers/nuclei-scan-provider): Vulnerability scanning with Nuclei - [httpx Scan Provider](/docs/services/cloud/providers/scan-providers/httpx-scan-provider): HTTP service probing with httpx - [Subfinder Scan Provider](/docs/services/cloud/providers/scan-providers/subfinder-scan-provider): Subdomain discovery with Subfinder - [ZAP Scan Provider](/docs/services/cloud/providers/scan-providers/zap-scan-provider): Web application security testing with OWASP ZAP - [OS Patch Scan Provider](/docs/services/cloud/providers/scan-providers/os-patch-scan-provider): System patch assessment and security update detection - Stores: Knowledge base document stores - [Overview](/docs/services/cloud/stores): Stores Overview - [Store Configuration](/docs/services/cloud/stores/store-configuration) - Vectors: Vector embeddings and similarity search - [Overview](/docs/services/cloud/vectors): Vectors Overview - [Vectors Generation](/docs/services/cloud/vectors/vectors-generation) - Chats: AI chat sessions and conversation management - [Overview](/docs/services/cloud/chats): Chats Overview - Connect: API compatibility and SDK integration - [Overview](/docs/services/cloud/connect): Learn about different ways to connect to and integrate with Hanzo Cloud. - [Using Hanzo Cloud OpenAI API Compatible Interface](/docs/services/cloud/connect/openai-api-compatibility): Learn how to connect external chat UIs to Hanzo Cloud using OpenAI API compatibility. - [Hanzo Cloud SDKs](/docs/services/cloud/connect/cloud-sdk): Learn how to integrate and use Hanzo Cloud SDKs with your applications. - Container Cloud: Kubernetes application management and templates - [Overview](/docs/services/cloud/container-cloud): Container Cloud Overview - [Template](/docs/services/cloud/container-cloud/kubernetes-templates) - Kubernetes Applications: Pre-built Kubernetes application deployments - [Application](/docs/services/cloud/container-cloud/kubernetes-applications) - [Creating Databases with KubeBlocks](/docs/services/cloud/container-cloud/kubernetes-applications/database) - Node Management: Remote node access via VNC and RDP - [Overview](/docs/services/cloud/node): Hanzo Cloud nodes Overview - [VNC](/docs/services/cloud/node/vnc): Hanzo Cloud nodes VNC - [RDP](/docs/services/cloud/node/rdp): Hanzo Cloud nodes RDP - Permissions: Access control for frontend and backend - [Permissions Overview](/docs/services/cloud/permissions): Understanding Hanzo Cloud's permission system - [Frontend Permissions](/docs/services/cloud/permissions/frontend-permissions): Frontend permission utilities in Hanzo Cloud - [Backend Permissions](/docs/services/cloud/permissions/backend-permissions): Backend permission utilities in Hanzo Cloud - Billing: Usage billing and transaction management - [Overview](/docs/services/cloud/billing): Billing and Usage Tracking - [Transactions](/docs/services/cloud/billing/transactions): Transaction tracking and billing integration - Forms: Form builders and configuration - [Forms Overview](/docs/services/cloud/forms): Introduction to Forms in Hanzo Cloud - [Form Configuration](/docs/services/cloud/forms/form-configuration): How to configure and customize forms in Hanzo Cloud - Graphs: Knowledge graphs and data visualization - [Graphs](/docs/services/cloud/graphs): Graph Visualization in Hanzo Cloud - Messages: Message handling and chat history - [Overview](/docs/services/cloud/messages): Messages Overview - Records: Data records and audit logging - [Records](/docs/services/cloud/records): Data records and aggregation - Scans: Security scanning and vulnerability assessment - [Scans](/docs/services/cloud/scans): Network and security scanning in Hanzo Cloud - Text Splitters: Document chunking and text splitting strategies - [Overview](/docs/services/cloud/textsplitters): Text Splitters Overview - Deployment: Deployment guides and configurations - [Deploy Hanzo IAM and Hanzo Cloud](/docs/services/cloud/deployment/deploy-iam-and-cloud): Discover how to deploy Hanzo IAM and Hanzo Cloud. - Developer Guide: Developer tools and API documentation - [Generating Swagger Files](/docs/services/cloud/developer-guide/swagger): Generating Swagger Files - [Hanzo Gateway](/docs/services/gateway): Unified API gateway and LLM proxy — routes to 100+ AI providers - [Hanzo Console](/docs/services/console): LLM engineering platform for observability, prompt management, evaluations, datasets, cost tracking, and session replay with distributed tracing. - Hanzo Platform - [Hanzo PaaS](/docs/services/platform): The platform.hanzo.ai control plane — deploy and operate applications, containers, and custom domains across your clusters, with IAM-native multi-org access. - Getting Started: Get up and running with Hanzo Platform - **Setup** - [Quickstart](/docs/services/platform/getting-started/quickstart): Deploy your first application in five minutes. - [Key Concepts](/docs/services/platform/getting-started/concepts): Organizations, projects, environments, and clusters explained. - [CLI Reference](/docs/services/platform/getting-started/cli): Install and use the Hanzo CLI for platform operations. - Deployments: Deploy applications with Kubernetes, Docker, and Git - **Orchestrators** - [Kubernetes Deployments](/docs/services/platform/deployments/kubernetes): Create Deployments, StatefulSets, and CronJobs on Kubernetes clusters with resource limits, health checks, and rolling updates. - [Docker Swarm](/docs/services/platform/deployments/docker-swarm): Deploy services on Docker Swarm clusters with overlay networking, rolling updates, and replica scaling. - [Docker Compose](/docs/services/platform/deployments/docker-compose): Deploy Compose stacks on single-node clusters with environment variables, volumes, and service networking. - **Build & Deploy** - [Git Deployments](/docs/services/platform/deployments/git-deployments): Push-to-deploy with GitHub, GitLab, and Bitbucket using Tekton pipelines and Kaniko builds. - [Container Registry](/docs/services/platform/deployments/container-registry): Configure pull credentials for GHCR, Docker Hub, ECR, and other private registries. - [Domains & TLS](/docs/services/platform/deployments/domains-tls): Add custom domains to your deployments with automatic TLS certificates from Let's Encrypt via cert-manager. - Clusters: Multi-cluster fleet management - [Fleet Overview](/docs/services/platform/clusters/fleet): Monitor health, resources, and workloads across all clusters from one dashboard. - [Register a Cluster](/docs/services/platform/clusters/register): Add existing Kubernetes clusters, Docker Swarm managers, and Docker hosts. - [Auto-Provisioning](/docs/services/platform/clusters/provisioning): Create managed Kubernetes clusters directly from the Hanzo Platform dashboard. - [Node Pools](/docs/services/platform/clusters/node-pools): Scale cluster capacity by adding, removing, and autoscaling node pools. - Virtual Machines: Launch and manage VMs on major cloud providers - [AWS EC2](/docs/services/platform/virtual-machines/aws): Launch and manage AWS EC2 instances from the Hanzo Platform dashboard. - [DigitalOcean](/docs/services/platform/virtual-machines/digitalocean): Launch and manage DigitalOcean Droplets from the Hanzo Platform dashboard. - [Hetzner Cloud](/docs/services/platform/virtual-machines/hetzner): Launch and manage Hetzner Cloud servers with excellent price/performance. - [Volumes](/docs/services/platform/virtual-machines/volumes): Create, attach, resize, and snapshot block storage volumes. - [Browser Terminal](/docs/services/platform/virtual-machines/terminal): Access VMs via a WebSocket-based browser terminal powered by Apache Guacamole. - Access Control: Organizations, teams, and permissions - [Organizations](/docs/services/platform/access-control/organizations): Create and manage organizations, switch between orgs, and configure org settings - [Roles](/docs/services/platform/access-control/roles): Organization roles and their permissions - [Cluster Permissions](/docs/services/platform/access-control/cluster-permissions): Per-cluster access control with manage, deploy, and view permissions - [Environment Protection](/docs/services/platform/access-control/environment-protection): Protection rules and approval workflows for production deployments - [Invitations](/docs/services/platform/access-control/invitations): Invite team members, manage pending invitations, and auto-accept behavior - Pricing: Plans and pricing details - [Plans](/docs/services/platform/pricing/plans): Cloud VM plans with vCPU, memory, and pricing details - [Compute](/docs/services/platform/pricing/compute): CPU and GPU compute pricing including NVIDIA T4, A100, and H100 instances - [Storage](/docs/services/platform/pricing/storage): Block storage pricing for SSD and NVMe volumes - API Reference - [API Reference](/docs/services/platform/api): Platform REST and tRPC API for managing organizations, clusters, containers, and VMs - [Authentication](/docs/services/platform/api/authentication): IAM tokens, API keys, and service tokens for the Hanzo PaaS API - [Organizations API](/docs/services/platform/api/organizations): Create, read, update, and delete organizations - [Clusters API](/docs/services/platform/api/clusters): Manage Kubernetes and Docker Swarm clusters via the API - [Containers API](/docs/services/platform/api/containers): Deploy, redeploy, and operate container workloads - [Virtual Machines API](/docs/services/platform/api/vms): Launch, manage, and destroy Visor VMs via the API - [Hanzo PaaS](/docs/services/paas): The platform.hanzo.ai control plane for deploying and operating services on Hanzo's Kubernetes clusters. - **AI & Models** - [Hanzo Chat](/docs/services/chat): AI chat platform with Zen models, 100+ third-party models, MCP tools, and agents - [Hanzo Studio](/docs/services/studio): Visual AI engine for image, video, 3D, and audio workflows with GPU scaling and node-based editing. - [Hanzo Flow](/docs/services/flow): Visual AI workflow builder for LLM applications - [Hanzo Auto](/docs/services/auto): AI-powered workflow automation platform with 600+ integrations - [Hanzo Operative](/docs/services/operative): Computer-use automation service that enables Claude to interact with a full desktop environment via screenshot capture, mouse/keyboard control, bash execution, and file editing tools. - [Hanzo Models](/docs/services/models): Model registry and catalog for AI inference across 376+ models from 58+ providers - [Hanzo Engine](/docs/services/engine): High-performance LLM inference engine — blazing-fast Rust-based serving with Metal/CUDA acceleration, quantization, vision, audio, and MCP tools - [Hanzo Search](/docs/services/search): AI-powered search engine built in Rust with sub-50ms response times, hybrid semantic/full-text search, faceted filtering, geo search, chat completions, and multi-language support. - [Hanzo Bot](/docs/services/bot): Skill-based AI assistant platform with 743+ skills, 35+ channel integrations, persona management, and a plugin SDK for extending capabilities. - [Hanzo Brain](/docs/services/brain): The brain.db substrate every Hanzo runtime hosts — pages, edges, facts, FTS5 hybrid search, BLAKE3 content-addressable ids, byte-identical across TypeScript, Go, C++, Python, and Rust. - [Hanzo Agents](/docs/services/agents): Multi-agent orchestration platform — 88 specialized agents, 15 workflow orchestrators, 42 development tools, native hanzo-mcp integration, and SDKs for Go, Python, and TypeScript. - [Hanzo Nexus](/docs/services/nexus): AI knowledge base and agent management platform - [Hanzo Vector](/docs/services/vector): High-performance vector search engine for AI applications - [Hanzo ML](/docs/services/ml): Kubeflow workflows and a Rust ML toolkit - **Identity & Security** - Hanzo IAM: Identity and Access Management - [Hanzo IAM](/docs/services/iam): Identity and Access Management for the Hanzo AI Platform - [Configuration](/docs/services/iam/configuration): Canonical IAM_* environment variable contract for services that consume Hanzo IAM. - Applications: Application configuration and management - [Overview](/docs/services/iam/application/overview): Learn how applications work in Hanzo IAM and how to configure authentication for your services. - [Application terminology](/docs/services/iam/application/terminology): Reference for application configuration fields and options. - [Application configuration](/docs/services/iam/application/config): Configure authentication and callback URLs for your Hanzo IAM applications. - [Providers](/docs/services/iam/application/providers): Attach providers to your application and set rules (signup, login, forgot password, MFA, etc.). - [Custom scopes](/docs/services/iam/application/scopes): Define custom OAuth scopes for Agent applications (e.g. MCP servers). - [Application categories](/docs/services/iam/application/categories): Default (user-facing) vs Agent (M2M) applications and their types. - [Application tags](/docs/services/iam/application/tags): Restrict sign-in to users whose tags match the application’s tags. - [Login UI customization](/docs/services/iam/application/ui-customization): Customize the sign-in page: background, panel style, position, and side panel. - [Sign-in methods](/docs/services/iam/application/signin-methods): Configure which sign-in methods are available and their order on the login page. - [Sign-in items table](/docs/services/iam/application/signin-items-table): Configure signin items to build a custom sign-in page. - [Sign-up items table](/docs/services/iam/application/signup-items-table): Configure signup items to build a custom registration page. - [Exclusive sign-in](/docs/services/iam/application/exclusive-signin): Allow only one active session per user per application. - [Specify login organization](/docs/services/iam/application/specify-login-organization): Let users choose or enter the organization on the sign-in page. - [Invitation codes](/docs/services/iam/application/invitation-code): Restrict application sign-up to users with a valid invitation code. - [Shared application](/docs/services/iam/application/shared-application): Use one application across multiple organizations with org-specific client IDs. - [Dynamic client registration](/docs/services/iam/application/dynamic-client-registration): Register OAuth clients programmatically via RFC 7591 (DCR). - The Basics: Core concepts, installation, and configuration - [Core concepts](/docs/services/iam/basic/core-concepts): Organizations, users, applications, and providers—the main building blocks of Hanzo IAM. - [Server installation](/docs/services/iam/basic/server-installation): Install and configure the Hanzo IAM server from source or pre-built binaries. - [Configuration](/docs/services/iam/basic/configuration): Configure the Hanzo IAM backend and frontend via app.conf and Conf.js. - [Try with Docker](/docs/services/iam/basic/try-with-docker): Run Hanzo IAM using Docker or Docker Compose for quick testing or production. - [Try with Helm](/docs/services/iam/basic/try-with-helm): Deploy Hanzo IAM on Kubernetes using Helm for manageable, scalable deployments. - [Public API](/docs/services/iam/basic/public-api): Authenticate and call the Hanzo IAM REST API from your apps and scripts. - [Tutorials](/docs/services/iam/basic/tutorials): Third-party product docs and articles that use Hanzo IAM for SSO or auth. - Organizations: Organization setup and customization - [Overview](/docs/services/iam/organization/overview): Organizations are the core unit in Hanzo IAM for managing users and applications. - [Account customization](/docs/services/iam/organization/accountCustomization): Control visibility and edit permissions for each user account field. - [Customize theme](/docs/services/iam/organization/customize-theme): Set primary color and border radius at global, organization, or application level. - [Password complexity](/docs/services/iam/organization/passwordComplexity): Configure password strength rules per organization. - [Password obfuscator](/docs/services/iam/organization/passwordObfuscator): Encrypt password parameters in login and set-password APIs. - [MFA items](/docs/services/iam/organization/mfa-items): Configure which MFA methods are available and whether they are optional or required. - [Organization tree](/docs/services/iam/organization/organization-tree): User groups and group hierarchy within an organization. - Users: User management, roles, and permissions - [Overview](/docs/services/iam/user/overview): User model, properties, roles, permissions, and bulk import in Hanzo IAM. - [Forms](/docs/services/iam/user/forms): Customize list-page columns and layout for core entities. - [User roles](/docs/services/iam/user/roles): Assign and manage roles for users; use roles with permission policies. - [User permissions](/docs/services/iam/user/permissions): Assign permissions to users and roles; use the Permissions API. - [MFA / 2FA](/docs/services/iam/user/multi-factor-authentication): Secure your account with MFA / 2FA - [User impersonation](/docs/services/iam/user/impersonation): Sign in as another user for support and testing without knowing their password. - Permissions: Permission models and Casbin integration - [Overview](/docs/services/iam/permission/overview): Use Casbin to manage fine-grained access control for users and resources in your organization. - [Permission configuration](/docs/services/iam/permission/permission-configuration): Configure Casbin permission policies and each field on the Edit Permission page. - [Exposed Casbin APIs](/docs/services/iam/permission/exposed-casbin-apis): Call Casbin from your backend to enforce and manage permissions. - [Adapter](/docs/services/iam/permission/adapter): Connect Casbin policy storage (database) and manage policies in the UI. - Providers: Identity, notification, payment, and storage providers - [Overview](/docs/services/iam/provider/overview): Configure third-party providers for OAuth, SMS, email, storage, payment, captcha, and more. - OAuth: OAuth identity provider integrations - [Overview](/docs/services/iam/provider/oauth/overview): Add OAuth providers so users can sign in with Google, GitHub, and other identity providers. - [Google OAuth](/docs/services/iam/provider/oauth/google): Add Google as an OAuth provider. - [GitHub OAuth](/docs/services/iam/provider/oauth/github): Add GitHub as an OAuth provider (web or device flow). - [Facebook OAuth](/docs/services/iam/provider/oauth/facebook): Add Facebook as an OAuth provider. - [Sign in with Apple](/docs/services/iam/provider/oauth/apple): Add Apple as an OAuth provider (Sign in with Apple). - [LinkedIn OAuth](/docs/services/iam/provider/oauth/linkedin): Add LinkedIn as an OAuth provider. - [Telegram](/docs/services/iam/provider/oauth/telegram): Add Telegram OAuth provider to your application - [Okta OAuth](/docs/services/iam/provider/oauth/okta): Add Okta as an OIDC/OAuth provider. - [Azure AD OAuth](/docs/services/iam/provider/oauth/azureAD): Add Microsoft Azure Active Directory as an OAuth provider. - [Azure AD B2C OAuth](/docs/services/iam/provider/oauth/azureADb2c): Add Azure AD B2C as an OAuth provider. - [AD FS OAuth](/docs/services/iam/provider/oauth/adfs): Add AD FS (Active Directory Federation Services) as an OAuth provider. - [GitLab OAuth](/docs/services/iam/provider/oauth/gitlab): Add GitLab (or self-hosted GitLab) as an OAuth provider. - [Gitee OAuth](/docs/services/iam/provider/oauth/gitee): Add Gitee as an OAuth provider. - [Google One Tap](/docs/services/iam/provider/oauth/googleonetap): Learn how to add Google One Tap support to your application - [DingTalk OAuth](/docs/services/iam/provider/oauth/DingTalk): Add DingTalk as an OAuth provider. - [Lark OAuth](/docs/services/iam/provider/oauth/lark): Add Lark (Feishu) as an OAuth provider. - [Baidu OAuth](/docs/services/iam/provider/oauth/baidu): Add Baidu as an OAuth provider. - [Alipay OAuth](/docs/services/iam/provider/oauth/Alipay): Add Alipay as an OAuth provider (certificate-based). - [WeChat OAuth](/docs/services/iam/provider/oauth/Wechat): Add WeChat as an OAuth provider (PC QR code or in-app browser). - [WeCom OAuth](/docs/services/iam/provider/oauth/weCom): Add WeCom (WeChat Work) as an OAuth provider for internal or third-party apps. - [Weibo OAuth](/docs/services/iam/provider/oauth/Weibo): Add Weibo as an OAuth provider. - [Tencent QQ OAuth](/docs/services/iam/provider/oauth/Tencent): Add Tencent QQ as an OAuth provider. - [Infoflow OAuth](/docs/services/iam/provider/oauth/infoflow): Add Baidu Infoflow as an OAuth provider. - [Steam OAuth](/docs/services/iam/provider/oauth/Steam): Add Steam as an OAuth provider (API key only). - [Custom OAuth provider](/docs/services/iam/provider/oauth/CustomProvider): Integrate any OAuth 2.0–compliant IdP (Custom through Custom10). - [OAuth user mapping](/docs/services/iam/provider/oauth/user-mapping): Map OAuth provider claims to Hanzo IAM user fields. - SAML: SAML identity provider integrations - [SAML provider overview](/docs/services/iam/provider/saml/overview): Sign in with external SAML 2.0 identity providers (Hanzo IAM as SP). - [Azure AD](/docs/services/iam/provider/saml/azure-ad): Using Azure AD as SAML IdP - [Google Workspace](/docs/services/iam/provider/saml/google-workspace): Using Google Workspace as SAML IdP - [Keycloak SAML](/docs/services/iam/provider/saml/keycloak): Use Keycloak as a SAML IdP for Hanzo IAM sign-in. - [Alibaba Cloud IDaaS SAML](/docs/services/iam/provider/saml/aliyun): Use Alibaba Cloud IDaaS (EIAM) as a SAML IdP for Hanzo IAM. - [Custom SAML](/docs/services/iam/provider/saml/custom): Connect any SAML 2.0 IdP to Hanzo IAM as the SP. - Email: Email provider integrations - [Email provider overview](/docs/services/iam/provider/email/overview): Configure SMTP for verification emails and password reset. - [SendGrid email](/docs/services/iam/provider/email/sendgrid): Use SendGrid as an email provider for verification and notifications. - [Azure Communication Services email](/docs/services/iam/provider/email/azureACS): Use Azure Communication Services (ACS) as the email provider. - [Brevo email](/docs/services/iam/provider/email/brevo): Use Brevo (Sendinblue) as the SMTP provider for Hanzo IAM. - [MailHog email](/docs/services/iam/provider/email/mailhog): Use MailHog as a local SMTP server for testing. - [Mailpit email](/docs/services/iam/provider/email/mailpit): Use Mailpit as a local SMTP server for testing. - SMS: SMS provider integrations - [SMS provider overview](/docs/services/iam/provider/sms/overview): Configure SMS providers for verification codes using go-sms-sender. - [Twilio SMS](/docs/services/iam/provider/sms/twilio): Use Twilio as an SMS provider for verification codes. - [Amazon SNS SMS](/docs/services/iam/provider/sms/amazonSns): Use Amazon SNS as an SMS provider for verification codes. - [Alibaba Cloud SMS](/docs/services/iam/provider/sms/alibabaCloud): Use Alibaba Cloud as an SMS provider for verification codes. - [Azure Communication Services SMS](/docs/services/iam/provider/sms/acs): Use Azure Communication Services (ACS) as an SMS provider. - Notification: Notification provider integrations - [Notification provider overview](/docs/services/iam/provider/notification/overview): Send notifications via Telegram, Slack, Discord, and other channels. - [Slack notification](/docs/services/iam/provider/notification/slack): Send Hanzo IAM notifications to a Slack channel. - [Discord notification](/docs/services/iam/provider/notification/discord): Use Discord as a notification provider (webhook-style). - [Telegram notification](/docs/services/iam/provider/notification/telegram): Send Hanzo IAM notifications to Telegram. - [Twitter (X) notification](/docs/services/iam/provider/notification/twitter): Use Twitter (X) as a notification provider. - [Google Chat notification](/docs/services/iam/provider/notification/googleChat): Use Google Chat as a notification provider via a service account. - [WeCom notification](/docs/services/iam/provider/notification/wecom): Use WeCom (WeChat Work) group bot webhooks for notifications. - [Custom HTTP notification](/docs/services/iam/provider/notification/customHttp): Send notifications to an arbitrary HTTP endpoint. - CAPTCHA: CAPTCHA provider integrations - [Captcha provider overview](/docs/services/iam/provider/captcha/overview): Add captcha to sign-in, sign-up, and password reset. - [Default captcha](/docs/services/iam/provider/captcha/default): Use Hanzo IAM’s built-in image captcha (digit sequence). - [reCAPTCHA](/docs/services/iam/provider/captcha/recaptcha): Add Google reCAPTCHA v2 Checkbox to your application. - [hCaptcha](/docs/services/iam/provider/captcha/hcaptcha): Add hCaptcha to your application as a captcha provider. - [Cloudflare Turnstile](/docs/services/iam/provider/captcha/cloudflareTurnstile): Add Cloudflare Turnstile captcha to your application. - [Alibaba Cloud Captcha](/docs/services/iam/provider/captcha/aliyunCaptcha): Add Alibaba Cloud Captcha to your application - [Geetest captcha](/docs/services/iam/provider/captcha/geetest): Add Geetest CAPTCHA V4 to your application. - Payment: Payment provider integrations - [Payment provider overview](/docs/services/iam/provider/payment/overview): Add payment providers so users can pay for products. - [Stripe payment](/docs/services/iam/provider/payment/stripe): Use Stripe as a payment provider in Hanzo IAM. - [PayPal payment](/docs/services/iam/provider/payment/paypal): Use PayPal as a payment provider in Hanzo IAM. - [Alipay](/docs/services/iam/provider/payment/Alipay): Add Alipay payment provider to your application - [WeChat Pay](/docs/services/iam/provider/payment/WeChatPay): Use WeChat Pay as a payment provider in Hanzo IAM. - [Adyen](/docs/services/iam/provider/payment/Adyen): Use Adyen as a payment provider for online, mobile, and in-store. - [AirWallex](/docs/services/iam/provider/payment/AirWallex): Use AirWallex as a payment provider. - [Balance payment](/docs/services/iam/provider/payment/Balance): Let users pay with their Hanzo IAM account balance (wallet). - [FastSpring](/docs/services/iam/provider/payment/FastSpring): Use FastSpring as a payment provider for digital products and subscriptions. - [Lemon Squeezy](/docs/services/iam/provider/payment/LemonSqueezy): Use Lemon Squeezy as a payment provider for subscriptions and one-time purchases. - [Paddle](/docs/services/iam/provider/payment/Paddle): Use Paddle as a payment provider for digital products and subscriptions. - [Polar](/docs/services/iam/provider/payment/Polar): Use Polar as a payment provider for digital products and subscriptions. - [Dummy payment](/docs/services/iam/provider/payment/dummy): Mock payment provider for testing and development. - Storage: Storage provider integrations - [Storage provider overview](/docs/services/iam/provider/storage/overview): Configure local or cloud storage for file uploads (e.g. avatars). - [Amazon S3 storage](/docs/services/iam/provider/storage/amazon-s3): Use Amazon S3 as a Hanzo IAM storage provider. - [MinIO storage](/docs/services/iam/provider/storage/minio): Use MinIO as a Hanzo IAM storage provider. - [Google Cloud Storage](/docs/services/iam/provider/storage/google-cloudstorage): Use Google Cloud Storage as a storage provider. - [Azure Blob storage](/docs/services/iam/provider/storage/azure): Use Azure Blob Storage as a storage provider. - [Alibaba Cloud OSS](/docs/services/iam/provider/storage/aliyun-oss): Use Alibaba Cloud OSS as a Hanzo IAM storage provider (static credentials or RRSA). - [Tencent Cloud COS](/docs/services/iam/provider/storage/tencentCloudCOS): Use Tencent Cloud COS as a Hanzo IAM storage provider. - [Synology NAS storage](/docs/services/iam/provider/storage/synology-nas): Use Synology NAS as a storage provider (S3-compatible). - [Local file system storage](/docs/services/iam/provider/storage/localFileSystem): Store uploaded files on the Hanzo IAM server’s filesystem. - Web3: Web3 wallet provider integrations - [MetaMask Web3](/docs/services/iam/provider/web3/metamask): Use MetaMask as a Web3 sign-in provider. - [Web3-Onboard](/docs/services/iam/provider/web3/web3onboard): Use Web3-Onboard to support multiple wallets for Web3 sign-in. - Face ID: Face ID verification providers - [Face ID overview](/docs/services/iam/provider/faceid/overview): Use Face ID as a sign-in method. - [Alibaba Cloud FaceBody](/docs/services/iam/provider/faceid/alibaba_cloud_facebody): Use Alibaba Cloud FaceBody for face verification. - Identity Verification: Identity verification providers - [ID verification provider overview](/docs/services/iam/provider/idv/overview): Verify user identity via third-party ID verification (KYC) providers. - [Alibaba Cloud](/docs/services/iam/provider/idv/alibaba-cloud): Integrate Alibaba Cloud for ID card verification - [Jumio ID verification](/docs/services/iam/provider/idv/jumio): Use Jumio as an ID verification (KYC) provider in Hanzo IAM. - MFA: Multi-factor authentication providers - [Push notification](/docs/services/iam/provider/mfa/push): Configure push notification provider for MFA - [RADIUS MFA](/docs/services/iam/provider/mfa/radius): Use an external RADIUS server as an MFA provider. - Tokens: Token management and configuration - [Overview](/docs/services/iam/token/overview): How Hanzo IAM uses OAuth tokens, JWT formats, and token lifecycle. - Sessions: Session management, SSO, and monitoring - [Overview](/docs/services/iam/session/overview): Understanding sessions in Hanzo IAM - [Single sign-on (SSO)](/docs/services/iam/session/single-sign-on): Let users sign in once and access all apps in the organization without signing in again. - [Single sign-out (SSO logout)](/docs/services/iam/session/single-sign-out): Log users out from all applications in the organization at once. - [Session management](/docs/services/iam/session/management): View and terminate user sessions in the Hanzo IAM admin panel. - Connecting to IAM: SDKs, protocols, and integration methods - [Overview](/docs/services/iam/how-to-connect/overview): Connect your application to Hanzo IAM using OAuth 2.0, OIDC, SAML, or CAS. - [Standard OIDC client](/docs/services/iam/how-to-connect/oidc-client): Connect to Hanzo IAM with any OIDC client using discovery endpoints. - [OIDC Flows](/docs/services/iam/how-to-connect/oidc-flows): Step-by-step guide to OpenID Connect authorization flows with Hanzo IAM — authorization code, PKCE, client credentials, device code, and token refresh. - [OAuth 2.0](/docs/services/iam/how-to-connect/oauth): Obtain, verify, and use access tokens with Hanzo IAM’s OAuth 2.0 endpoints. - [Hanzo IAM SDKs](/docs/services/iam/how-to-connect/sdk): Use Hanzo IAM SDKs for frontend and backend integration with user management and more. - [Vue SDK](/docs/services/iam/how-to-connect/vue-sdk): Use Hanzo IAM in Vue 2 or Vue 3 with the official Vue SDK. - [Next.js](/docs/services/iam/how-to-connect/nextjs): Integrate Hanzo IAM in a Next.js app with middleware and the JS SDK. - [Nuxt](/docs/services/iam/how-to-connect/nuxt): Integrate Hanzo IAM in a Nuxt app with middleware and the JS SDK. - [Hanzo IAM CLI](/docs/services/iam/how-to-connect/cli): Using Hanzo IAM's official command-line interface for managing users, groups, and permissions - [Plugins and middlewares](/docs/services/iam/how-to-connect/plugin): Official Hanzo IAM plugins for Spring Boot, WordPress, Odoo, Django, and Chrome. - [Chrome extension](/docs/services/iam/how-to-connect/chrome-extension): Integrate Hanzo IAM OAuth in a Chrome extension. - [Hanzo IAM as a CAS server](/docs/services/iam/how-to-connect/cas): Use Hanzo IAM as a Central Authentication Service (CAS) server for CAS 1.0, 2.0, and 3.0. - [WebAuthn](/docs/services/iam/how-to-connect/webauthn): Sign in with WebAuthn (passkeys, fingerprint, face, security keys). - [Face ID](/docs/services/iam/how-to-connect/face-id): Sign in with Face ID using face-api.js. - [Hanzo IAM authenticator app](/docs/services/iam/how-to-connect/totp-authenticator-app): TOTP authenticator app for iOS and Android, synced with Hanzo IAM. - [Guest authentication](/docs/services/iam/how-to-connect/guest-auth): Create temporary users without credentials and upgrade them later. - Desktop SDKs: Desktop application integration - [Electron app](/docs/services/iam/how-to-connect/desktop-sdks/electron-app): Integrate Hanzo IAM in an Electron app with OAuth and a custom protocol. - [.NET desktop app](/docs/services/iam/how-to-connect/desktop-sdks/dotnet-app): Integrate Hanzo IAM in a .NET desktop app with WebView2. - [.NET MAUI app](/docs/services/iam/how-to-connect/desktop-sdks/maui-app): Integrate Hanzo IAM in a .NET MAUI app (Android, Windows, etc.) with OpenID Connect. - [Qt desktop app](/docs/services/iam/how-to-connect/desktop-sdks/qt-app): Integrate Hanzo IAM in a Qt (C++) desktop app with WebEngine. - Mobile SDKs: Mobile application integration - [React Native app](/docs/services/iam/how-to-connect/mobile-sdks/react-native-app): Integrate Hanzo IAM in a React Native app with the official SDK. - SAML: SAML-based service provider integrations - [SAML IdP overview](/docs/services/iam/how-to-connect/saml/overview): Use Hanzo IAM as a SAML 2.0 identity provider. - [AWS Client VPN (SAML)](/docs/services/iam/how-to-connect/saml/aws): Use Hanzo IAM as SAML IdP for AWS Client VPN. - [Google Workspace (SAML)](/docs/services/iam/how-to-connect/saml/google-workspace): Use Hanzo IAM as SAML IdP for Google Workspace SSO. - [Keycloak (SAML)](/docs/services/iam/how-to-connect/saml/keycloak): Use Hanzo IAM as SAML IdP in Keycloak. - [Appgate (SAML POST)](/docs/services/iam/how-to-connect/saml/appgate): Use Hanzo IAM as SAML IdP for Appgate SDP (POST SAMLResponse). - [Tencent Cloud (SAML)](/docs/services/iam/how-to-connect/saml/tencent-cloud): Use Hanzo IAM as SAML IdP for Tencent Cloud CAM. - MCP: Model Context Protocol connection guide - [MCP server overview](/docs/services/iam/how-to-connect/mcp/overview): Use Hanzo IAM’s MCP server for programmatic access via JSON-RPC 2.0. - [MCP authentication](/docs/services/iam/how-to-connect/mcp/authentication): OAuth discovery and authentication methods for the MCP server. - [MCP authorization and scopes](/docs/services/iam/how-to-connect/mcp/authorization): Scope-based access control for MCP tools. - [MCP integration example](/docs/services/iam/how-to-connect/mcp/integration): Python example: scoped token and MCP tool calls. - [MCP tools reference](/docs/services/iam/how-to-connect/mcp/tools): List and call MCP tools (applications and more). - [Connect Claude Desktop to MCP](/docs/services/iam/how-to-connect/mcp/connect-claude-desktop): Connect Claude Desktop to Hanzo IAM’s MCP server with OAuth. - [Connect Cursor to MCP](/docs/services/iam/how-to-connect/mcp/connect-cursor): Connect Cursor IDE to Hanzo IAM’s MCP server with OAuth. - [Connect ChatGPT to MCP](/docs/services/iam/how-to-connect/mcp/connect-chatgpt): Connect ChatGPT to Hanzo IAM’s MCP server with OAuth. - [MCP error handling](/docs/services/iam/how-to-connect/mcp/error-handling): JSON-RPC error codes and responses from the MCP server. - [MCP troubleshooting](/docs/services/iam/how-to-connect/mcp/troubleshooting): Common MCP and OAuth issues and how to debug them. - Integrations: Third-party application integrations by language - Go: Go application integrations - [Grafana](/docs/services/iam/integration/go/grafana): Use Hanzo IAM as the OAuth provider for Grafana sign-in. - [Gitea](/docs/services/iam/integration/go/gitea): Use Hanzo IAM as the OAuth/OIDC provider for Gitea sign-in. - [MinIO](/docs/services/iam/integration/go/minio): Configuring Hanzo IAM as an identity provider to support MinIO - [Portainer](/docs/services/iam/integration/go/portainer): Using Hanzo IAM for authentication in Portainer - [Kubernetes](/docs/services/iam/integration/go/kubernetes): Using Hanzo IAM for Authentication in Kubernetes - [OpenShift](/docs/services/iam/integration/go/openshift): Using Hanzo IAM for authentication in OpenShift - [Traefik](/docs/services/iam/integration/go/traefik): Protect services behind Traefik with Hanzo IAM auth (SSO). - [Bytebase](/docs/services/iam/integration/go/Bytebase): Use Hanzo IAM as the OAuth2/OIDC provider for Bytebase SSO. - [BookStack](/docs/services/iam/integration/go/bookstack): Using Hanzo IAM for authentication in BookStack - [ELK](/docs/services/iam/integration/go/elk): Overview of iam/elk-auth-iam - Java: Java application integrations - [Spring Boot](/docs/services/iam/integration/java/spring-boot): Using Hanzo IAM in a Spring Boot project - [Spring Cloud](/docs/services/iam/integration/java/spring-cloud): Using Hanzo IAM in Spring Cloud - [Spring Cloud Gateway](/docs/services/iam/integration/java/spring-cloud-gateway): Using Hanzo IAM in Spring Cloud Gateway - Spring Security: Spring Security integration guides - [Spring Security OAuth](/docs/services/iam/integration/java/spring-security/spring-security-oauth): Using Spring Security as an example to demonstrate how to use OIDC to connect to your applications - [Spring Security filter (OIDC)](/docs/services/iam/integration/java/spring-security/spring-security-filter): Integrate Hanzo IAM with Spring Security using OIDC. - [Jenkins (OIDC)](/docs/services/iam/integration/java/jenkins-oidc): Use Hanzo IAM as the OIDC IdP for Jenkins sign-in. - [Jenkins plugin](/docs/services/iam/integration/java/jenkins-plugin): Using the Hanzo IAM plugin for Jenkins security - [Connecting applications with OIDC protocol - Confluence](/docs/services/iam/integration/java/Confluence): Learn how to use OIDC protocol as IDP to connect Confluence and other applications. - [Using the miniOrange plugin](/docs/services/iam/integration/java/jira): Connect iam and Jira using the OIDC protocol as the IDP - [Via built-in SSO](/docs/services/iam/integration/java/jira2): Using the OIDC protocol as an IDP to connect various applications, such as Jira - [Cloud Foundry](/docs/services/iam/integration/java/CloudFoundry): Learn how to integrate Hanzo IAM with Cloud Foundry to secure your applications. - [Apache DolphinScheduler](/docs/services/iam/integration/java/dolphinscheduler): Using Hanzo IAM for DolphinScheduler SSO login - [FireZone](/docs/services/iam/integration/java/firezone): Using the OIDC protocol as the IDP to connect various applications, such as FireZone - [Apache IoTDB](/docs/services/iam/integration/java/iotdb): Using Hanzo IAM with Apache IoTDB - [Pulsar manager](/docs/services/iam/integration/java/Pulsar-manager): Using Hanzo IAM in Pulsar Manager - [RuoYi](/docs/services/iam/integration/java/RuoYi): Using Hanzo IAM in RuoYi-Cloud - [ShardingSphere](/docs/services/iam/integration/java/ShardingSphere): Using Hanzo IAM in ShardingSphere - [Using Hanzo IAM in ShenYu](/docs/services/iam/integration/java/shenyu): How to use Hanzo IAM with ShenYu - [Thingsboard](/docs/services/iam/integration/java/Thingsboard): Learn how to integrate Hanzo IAM with Thingsboard to secure your applications - JavaScript: JavaScript application integrations - [Firebase](/docs/services/iam/integration/javascript/firebase): Firebase project using Hanzo IAM as Identity Provider - [WeChat mini program](/docs/services/iam/integration/javascript/wechat_miniprogram): Integrate Hanzo IAM sign-in in a WeChat Mini Program (no OAuth redirect). - Python: Python application integrations - [JumpServer](/docs/services/iam/integration/python/JumpServer): Using CAS to connect JumpServer - Ruby: Ruby application integrations - [GitLab](/docs/services/iam/integration/ruby/gitlab): Using Hanzo IAM for authentication in a self-developed GitLab server - PHP: PHP application integrations - [WordPress (CAS SSO)](/docs/services/iam/integration/php/WordPress): Use Hanzo IAM as CAS IdP for WordPress with the wp-cassify plugin. - [Flarum](/docs/services/iam/integration/php/Flarum): Using OAuth2 to connect various applications, like Flarum - [Moodle](/docs/services/iam/integration/php/Moodle): Using OAuth to connect Moodle - [Zabbix](/docs/services/iam/integration/php/Zabbix): Use Hanzo IAM as the SAML IdP for Zabbix SSO. - [Using Hanzo IAM as an OAuth2 server in ShowDoc](/docs/services/iam/integration/php/showdoc): Using Hanzo IAM as an OAuth2 server in ShowDoc - [Zentao](/docs/services/iam/integration/php/zentao): Using Hanzo IAM for authentication in Zentao - C#: C# application integrations - [Unity](/docs/services/iam/integration/CSharp/Unity): Use the Hanzo IAM-dotnet-sdk for Unity development. - Lua: Lua application integrations - [APISIX](/docs/services/iam/integration/lua/apisix): Using Hanzo IAM in APISIX - Haskell: Haskell application integrations - [Hasura](/docs/services/iam/integration/Haskell/Hasura) - Syncer: User synchronization with external directories - [Overview](/docs/services/iam/syncer/overview): Sync users from external systems (databases, Azure AD, Keycloak, etc.) into Hanzo IAM. - [Database syncer](/docs/services/iam/syncer/Database): Sync user data from an external database into Hanzo IAM. - [Azure AD syncer](/docs/services/iam/syncer/AzureAD): Sync users from Azure Active Directory (Microsoft Entra ID) to Hanzo IAM via Microsoft Graph. - [Active Directory syncer](/docs/services/iam/syncer/ActiveDirectory): Sync users from Microsoft Active Directory to Hanzo IAM via LDAP/LDAPS. - [Google Workspace syncer](/docs/services/iam/syncer/GoogleWorkspace): Sync users from Google Workspace to Hanzo IAM via the Admin SDK Directory API. - [Keycloak syncer](/docs/services/iam/syncer/Keycloak): Sync users from Keycloak to Hanzo IAM with automatic schema mapping. - [DingTalk syncer](/docs/services/iam/syncer/DingTalk): Sync users from DingTalk (钉钉) to Hanzo IAM via the DingTalk API. - [WeCom syncer](/docs/services/iam/syncer/WeCom): Sync users from WeCom (企业微信) to Hanzo IAM via the WeCom API. - Deployment: Deploying IAM in various environments - [Deploying with Docker](/docs/services/iam/deployment/docker): Run Hanzo IAM with Docker or Docker Compose and optional reverse proxies. - [Deploying behind Nginx](/docs/services/iam/deployment/nginx): Put Nginx in front of the Hanzo IAM backend to serve and proxy traffic. - [Deploying to Kubernetes](/docs/services/iam/deployment/k8s): Deploy Hanzo IAM in a Kubernetes cluster using the example manifests. - [Data initialization](/docs/services/iam/deployment/data-initialization): Initialize or migrate Hanzo IAM data using JSON config files. - [Hosting static files in a CDN](/docs/services/iam/deployment/deploy-cdn): Deploy Hanzo IAM frontend static assets to a CDN using a storage provider. - [Hosting static files on an intranet](/docs/services/iam/deployment/deploy-intranet): Serve Hanzo IAM static assets from an intranet-accessible URL. - [Database migration](/docs/services/iam/deployment/db-migration): How Hanzo IAM handles database schema and data migrations. - [Version information](/docs/services/iam/deployment/version-info): How Hanzo IAM reports its version for binaries, Docker, and git builds. - Monitoring: Monitoring and observability - [Web UI monitoring](/docs/services/iam/monitoring/Web-UI): View Hanzo IAM runtime metrics in the web UI. - [Prometheus](/docs/services/iam/monitoring/Prometheus): Scrape Hanzo IAM metrics with Prometheus. - [KMS Integration](/docs/services/iam/kms-integration): How Hanzo IAM stores and reads its secrets from Hanzo KMS - [MPC Authentication](/docs/services/iam/mpc): Multi-Party Computation authentication for secure key recovery - MCP Auth: Model Context Protocol authentication - [Hanzo IAM as MCP Auth Provider](/docs/services/iam/mcp-auth/overview): Use Hanzo IAM as an external OAuth 2.1 authorization server for third-party MCP servers - [MCP auth setup](/docs/services/iam/mcp-auth/setup): Configure Hanzo IAM as the OAuth server for your MCP server. - [Third-party MCP server integration](/docs/services/iam/mcp-auth/third-party-integration): Runnable code examples for MCP servers using Hanzo IAM OAuth (Python, Node.js, Go). - LDAP: LDAP configuration and server - [Overview](/docs/services/iam/ldap/overview): Sync users from an LDAP server into Hanzo IAM and authenticate them against LDAP. - [LDAP configuration and sync](/docs/services/iam/ldap/config): Configure LDAP per organization and sync users into Hanzo IAM. - [LDAP server](/docs/services/iam/ldap/ldapserver): Use Hanzo IAM as an LDAP server for bind and search. - RADIUS: RADIUS protocol support - [Overview](/docs/services/iam/radius/overview): Run Hanzo IAM as a RADIUS server for network access and accounting. - SCIM: SCIM user provisioning protocol - [Overview](/docs/services/iam/scim/overview): Provision and manage users in Hanzo IAM via the SCIM 2.0 API. - Webhooks: Webhook event notifications - [Webhooks](/docs/services/iam/webhooks/overview): Send Hanzo IAM events to your application via HTTP webhooks for real-time integration. - IP Whitelist: IP-based access control - [IP allowlist](/docs/services/iam/ip-whitelist/ip-whitelist): Restrict access to login, sign-up, and forgot-password pages by client IP. - Invitations: User invitation management - [Overview](/docs/services/iam/invitation/overview): Restrict sign-up to users who have a valid invitation code. - Certificates: Certificate management - [Overview](/docs/services/iam/cert/overview): Use certificates in Hanzo IAM for JWT signing, SAML, and payment provider security. - Pricing: Plans, subscriptions, and billing - [Overview](/docs/services/iam/pricing/overview): Use Hanzo IAM for subscription and pricing: plans, payments, and subscriptions. - [Plan](/docs/services/iam/pricing/plan): Define a plan’s features and price; plans are tied to roles and products. - [Pricing](/docs/services/iam/pricing/pricing): Group one or more plans so users can sign up at different price points. - [Subscription](/docs/services/iam/pricing/subscription): Manage a user’s selected plan and application access. - [Transaction](/docs/services/iam/pricing/transaction): Track payments and balance changes for users and organizations. - Products: Product and commerce management - [Product](/docs/services/iam/products/product): Define products (or services) to sell and attach payment providers. - [Product store](/docs/services/iam/products/product-store): Publish products to a storefront where users can browse and purchase - [Shopping cart](/docs/services/iam/products/cart): Collect multiple products before purchasing them together - [Order](/docs/services/iam/products/order): Track and manage product purchases with orders - [Payment](/docs/services/iam/products/payment): View payment records, states, and issue invoices. - Resources: Resource management - [Overview](/docs/services/iam/resources/overview): Upload and manage files and images as resources using a storage provider. - Developer Guide: Development setup and API documentation - [Frontend](/docs/services/iam/developer-guide/frontend): Hanzo IAM web UI source layout and how to run or customize it. - [Generating Swagger docs](/docs/services/iam/developer-guide/swagger): Generate Swagger/OpenAPI docs for Hanzo IAM APIs using the modified bee tool. - [Contributor guide](/docs/services/iam/contributing): How to contribute to Hanzo IAM: code, documentation, and community. - [Internationalization](/docs/services/iam/internationalization): Hanzo IAM’s supported languages and how to contribute translations. - [Hanzo Identity](/docs/services/identity): User identity, profiles, and directory services - [Hanzo DID](/docs/services/did): Decentralized identity, profiles, and directory services - Hanzo KMS: Key Management Service - [Hanzo KMS](/docs/services/kms): Key Management Service for secrets, machine-identity access, and threshold signing keys - [Service Integration](/docs/services/kms/service-integration): How Hanzo services consume secrets from KMS using KMSSecret CRDs and Universal Auth - [Universal Auth](/docs/services/kms/universal-auth): Machine Identity authentication for service-to-KMS communication - [KMSSecret CRD](/docs/services/kms/kmssecret-crd): Kubernetes Custom Resource for automatic secret synchronization from KMS - Getting Started: Get up and running with Hanzo KMS - [Overview](/docs/services/kms/getting-started/overview): The open source platform for managing secrets, certificates, and secure infrastructure access. - [What is Hanzo KMS?](/docs/services/kms/getting-started/introduction): The open source platform for managing secrets, certificates, and secure infrastructure access. - [CLI](/docs/services/kms/getting-started/cli) - [Docker](/docs/services/kms/getting-started/docker) - [SDKs](/docs/services/kms/getting-started/sdks) - Concepts: Core concepts of Hanzo KMS - [Platform Hierarchy](/docs/services/kms/getting-started/concepts/platform-hierarchy): Understand how organizations and projects are structured in Hanzo KMS. - [Platform Identity and Access Management](/docs/services/kms/getting-started/concepts/platform-iam): Understand how users, machine identities, roles, and permissions are managed. - [Client Ecosystem](/docs/services/kms/getting-started/concepts/client-integrations): Get an overview of the CLI, SDKs, agents, APIs, and integrations that interact with Hanzo KMS. - [Using Hanzo KMS: Cloud or Self-Hosted](/docs/services/kms/getting-started/concepts/deployment-models): Choose between Hanzo KMS Cloud or a self-managed deployment - [Audit Logs](/docs/services/kms/getting-started/concepts/audit-logs): Understand how Hanzo KMS logs activity and supports external audit streaming. - Platform: KMS platform features and configuration - [Sign up](/docs/services/kms/platform/create-account): How to create an account in Hanzo KMS? - [Overview](/docs/services/kms/platform/organization): Learn more and understand the concept of Hanzo KMS organizations. - [Overview](/docs/services/kms/platform/project): Learn more and understand the concept of Hanzo KMS projects. - [Project Templates](/docs/services/kms/platform/project-templates): Learn how to manage and apply project templates - [Enhancing Security and Usability: Project Upgrades](/docs/services/kms/platform/project-upgrade) - [Folders](/docs/services/kms/platform/folder): Learn how to organize secrets with folders. - [Service Token](/docs/services/kms/platform/token): Hanzo KMS service tokens allow users to programmatically interact with Hanzo KMS. - [Secret Referencing and Importing](/docs/services/kms/platform/secret-reference): Learn the fundamentals of secret referencing and importing in Hanzo KMS. - [Secret Sharing](/docs/services/kms/platform/secret-sharing): Learn how to share time & view-count bound secrets securely with anyone on the internet. - [Secret Versioning](/docs/services/kms/platform/secret-versioning): Learn how secret versioning works in Hanzo KMS. - [Approval Workflows](/docs/services/kms/platform/pr-workflows): Learn how to enable a set of policies to manage changes to sensitive secrets and environments. - [Point-in-Time Recovery](/docs/services/kms/platform/pit-recovery): Learn how to rollback secrets and configurations to any snapshot with Hanzo KMS. - [Multi-factor Authentication](/docs/services/kms/platform/mfa): Learn how to secure your Hanzo KMS account with MFA. - [Groups](/docs/services/kms/platform/groups): Manage groups containing users and machine identities in Hanzo KMS. - [GitHub Team Sync](/docs/services/kms/platform/github-org-sync): Learn how to automatically synchronize your GitHub teams with Hanzo KMS Groups. - [Sub-Organizations](/docs/services/kms/platform/sub-organizations): Learn how to use sub-organizations to create autonomous units within your organization. - [Overview](/docs/services/kms/platform/audit-logs): Track all actions performed within Hanzo KMS - [Event Subscriptions](/docs/services/kms/platform/event-subscriptions): Subscribe to events in Hanzo KMS for real-time updates - [Webhooks](/docs/services/kms/platform/webhooks): Learn the fundamentals of Hanzo KMS webhooks. - Secrets Management: Core secrets management features - [Secrets Management](/docs/services/kms/platform/secrets-mgmt/overview): Learn how to securely store, access, and manage sensitive application secrets. - [Projects](/docs/services/kms/platform/secrets-mgmt/project): Learn more and understand the concept of Hanzo KMS projects. - Concepts: Secrets management concepts - [Secrets Management](/docs/services/kms/platform/secrets-mgmt/concepts/secrets-mgmt): Learn what is secrets management and why it matters for building secure systems. - [Scoping Secrets](/docs/services/kms/platform/secrets-mgmt/concepts/access-control): Learn how access to secrets is controlled in Hanzo KMS. - [Fetching Secrets](/docs/services/kms/platform/secrets-mgmt/concepts/secrets-delivery): Learn how to deliver secrets from Hanzo KMS into the systems, applications, and environments that need them. - [Secrets Rotation](/docs/services/kms/platform/secrets-mgmt/concepts/secrets-rotation): Learn what secrets rotation is, why it matters, and how Hanzo KMS enables it. - [Dynamic Secrets](/docs/services/kms/platform/secrets-mgmt/concepts/dynamic-secrets): Learn what dynamic secrets are, why they're useful, and how Hanzo KMS enables them. - Access Controls: Role-based and attribute-based access control - [Access Controls](/docs/services/kms/platform/access-controls/overview): Learn about Hanzo KMS's access control toolset. - [Role-based Access Controls](/docs/services/kms/platform/access-controls/role-based-access-controls): Learn how to use RBAC to manage user permissions. - [Additional Privileges](/docs/services/kms/platform/access-controls/additional-privileges): Learn how to add specific privileges on top of predefined roles. - [Temporary Access](/docs/services/kms/platform/access-controls/temporary-access): Learn how to set up timed access to sensitive resources for user and machine identities. - [Access Requests](/docs/services/kms/platform/access-controls/access-requests): Learn how to request access to sensitive resources in Hanzo KMS. - [Project Access Requests](/docs/services/kms/platform/access-controls/project-access-requests): Learn how to request access to projects in Hanzo KMS. - [Assume Privileges](/docs/services/kms/platform/access-controls/assume-privilege): Learn how to temporarily assume the privileges of a user or machine identity within a project. - Attribute-Based Access Control: ABAC policies and attribute management - [Overview](/docs/services/kms/platform/access-controls/abac/overview): Learn the basics of ABAC for both users and machine identities. - [Users identities](/docs/services/kms/platform/access-controls/abac/managing-user-metadata): How to set and use metadata attributes on user identities for ABAC. - [Machine identities](/docs/services/kms/platform/access-controls/abac/managing-machine-identity-attributes): Learn how to set metadata and leverage authentication attributes for machine identities. - Identities: Machine and user identity management - [User and Machine Identities](/docs/services/kms/platform/identities/overview): Learn more about identities to interact with resources in Hanzo KMS. - [User Identities](/docs/services/kms/platform/identities/user-identities): Read more about the concept of user identities in Hanzo KMS. - [Machine Identities](/docs/services/kms/platform/identities/machine-identities): Learn how to use Machine Identities to programmatically interact with Hanzo KMS. - [Universal Auth](/docs/services/kms/platform/identities/universal-auth): Learn how to authenticate to Hanzo KMS from any platform or environment. - [Token Auth](/docs/services/kms/platform/identities/token-auth): Learn how to authenticate to Hanzo KMS from any platform or environment using an access token. - [JWT Auth](/docs/services/kms/platform/identities/jwt-auth): Learn how to authenticate with Hanzo KMS using JWT-based authentication. - [AWS Auth](/docs/services/kms/platform/identities/aws-auth): Learn how to authenticate with Hanzo KMS for EC2 instances, Lambda functions, and other IAM principals. - [Azure Auth](/docs/services/kms/platform/identities/azure-auth): Learn how to authenticate with Hanzo KMS for services on Azure - [GCP Auth](/docs/services/kms/platform/identities/gcp-auth): Learn how to authenticate with Hanzo KMS for services on Google Cloud Platform - [Kubernetes Auth](/docs/services/kms/platform/identities/kubernetes-auth): Learn how to authenticate with Hanzo KMS in Kubernetes - [Alibaba Cloud Auth](/docs/services/kms/platform/identities/alicloud-auth): Learn how to authenticate with Hanzo KMS using Alibaba Cloud user accounts. - [OCI Auth](/docs/services/kms/platform/identities/oci-auth): Learn how to authenticate with Hanzo KMS using OCI user accounts. - [TLS Certificate Auth](/docs/services/kms/platform/identities/tls-cert-auth): Learn how to authenticate with Hanzo KMS using TLS Certificate. - [Machine Identity Auth Templates](/docs/services/kms/platform/identities/auth-templates): Learn how to use auth templates to standardize authentication configurations for machine identities. - OIDC Auth: OIDC authentication for machine identities - [General](/docs/services/kms/platform/identities/oidc-auth/general): Learn how to authenticate with Hanzo KMS from any platform or environment using OpenID Connect (OIDC). - [Github](/docs/services/kms/platform/identities/oidc-auth/github): Learn how to authenticate Github workflows with Hanzo KMS using OpenID Connect (OIDC). - [GitLab](/docs/services/kms/platform/identities/oidc-auth/gitlab): Learn how to authenticate GitLab pipelines with Hanzo KMS using OpenID Connect (OIDC). - [Azure](/docs/services/kms/platform/identities/oidc-auth/azure): Learn how to authenticate Azure pipelines with Hanzo KMS using OpenID Connect (OIDC). - [CircleCI](/docs/services/kms/platform/identities/oidc-auth/circleci): Learn how to authenticate CircleCI jobs with Hanzo KMS using OpenID Connect (OIDC). - [Terraform Cloud](/docs/services/kms/platform/identities/oidc-auth/terraform-cloud): How to authenticate with Hanzo KMS from Terraform Cloud using OIDC. - [SPIFFE/SPIRE](/docs/services/kms/platform/identities/oidc-auth/spire): Learn how to authenticate SPIRE workloads with Hanzo KMS using OpenID Connect (OIDC). - LDAP Auth: LDAP authentication for machine identities - [General](/docs/services/kms/platform/identities/ldap-auth/general): Learn how to authenticate with Hanzo KMS using LDAP. - [JumpCloud](/docs/services/kms/platform/identities/ldap-auth/jumpcloud): Learn how to authenticate with Hanzo KMS using LDAP with JumpCloud. - Authentication Methods: User authentication methods - [Email and Password](/docs/services/kms/platform/auth-methods/email-password): Learn how to authenticate into Hanzo KMS with email and password. - SSO: Single sign-on integrations - [SSO Overview](/docs/services/kms/platform/sso/overview): Learn how to log in to Hanzo KMS via SSO protocols. - [Google SSO](/docs/services/kms/platform/sso/google): Learn how to configure Google SSO for Hanzo KMS. - [Google SAML](/docs/services/kms/platform/sso/google-saml): Learn how to configure Google SAML for Hanzo KMS SSO. - [GitHub SSO](/docs/services/kms/platform/sso/github): Learn how to configure GitHub SSO for Hanzo KMS. - [GitLab SSO](/docs/services/kms/platform/sso/gitlab): Learn how to configure GitLab SSO for Hanzo KMS. - [Okta SAML](/docs/services/kms/platform/sso/okta): Learn how to configure Okta SAML 2.0 for Hanzo KMS SSO. - [Okta OIDC](/docs/services/kms/platform/sso/okta-oidc): Learn how to configure Okta OIDC for Hanzo KMS SSO. - [Entra ID / Azure AD SAML](/docs/services/kms/platform/sso/azure): Learn how to configure Microsoft Entra ID for Hanzo KMS SSO. - [JumpCloud SAML](/docs/services/kms/platform/sso/jumpcloud): Learn how to configure JumpCloud SAML for Hanzo KMS SSO. - [Keycloak SAML](/docs/services/kms/platform/sso/keycloak-saml): Learn how to configure Keycloak SAML for Hanzo KMS SSO. - [Auth0 SAML](/docs/services/kms/platform/sso/auth0-saml): Learn how to configure Auth0 SAML for Hanzo KMS SSO. - [Auth0 OIDC](/docs/services/kms/platform/sso/auth0-oidc): Learn how to configure Auth0 OIDC for Hanzo KMS SSO. - [PingOne OIDC](/docs/services/kms/platform/sso/pingone-oidc): Learn how to configure PingOne OIDC for Hanzo KMS SSO. - General OIDC: Generic OIDC provider configuration - [General OIDC](/docs/services/kms/platform/sso/general-oidc/overview): Learn how to configure OIDC for Hanzo KMS SSO with any OIDC-compliant identity provider - [General OIDC Group Membership Mapping](/docs/services/kms/platform/sso/general-oidc/group-membership-mapping): Learn how to sync OIDC group members to matching groups in Hanzo KMS. - Keycloak OIDC: Keycloak OIDC provider configuration - [Keycloak OIDC Overview](/docs/services/kms/platform/sso/keycloak-oidc/overview): Learn how to configure Keycloak OIDC for Hanzo KMS SSO. - [Keycloak OIDC Group Membership Mapping](/docs/services/kms/platform/sso/keycloak-oidc/group-membership-mapping): Learn how to sync Keycloak group members to matching groups in Hanzo KMS. - SCIM: SCIM provisioning and group sync - [SCIM Overview](/docs/services/kms/platform/scim/overview): Learn how to provision users for Hanzo KMS via SCIM. - [Okta SCIM](/docs/services/kms/platform/scim/okta): Learn how to configure SCIM provisioning with Okta for Hanzo KMS. - [Azure SCIM](/docs/services/kms/platform/scim/azure): Learn how to configure SCIM provisioning with Azure for Hanzo KMS. - [JumpCloud SCIM](/docs/services/kms/platform/scim/jumpcloud): Learn how to configure SCIM provisioning with JumpCloud for Hanzo KMS. - [PingOne SCIM](/docs/services/kms/platform/scim/pingone): Learn how to configure SCIM provisioning with PingOne for Hanzo KMS. - [SCIM Group Mappings](/docs/services/kms/platform/scim/group-mappings): Learn how to enhance your SCIM implementation using group mappings - LDAP: LDAP directory integration - [LDAP Overview](/docs/services/kms/platform/ldap/overview): Learn how to authenticate into Hanzo KMS with LDAP. - [General LDAP](/docs/services/kms/platform/ldap/general): Learn how to log in to Hanzo KMS with LDAP. - [JumpCloud LDAP](/docs/services/kms/platform/ldap/jumpcloud): Learn how to configure JumpCloud LDAP for authenticating into Hanzo KMS. - Dynamic Secrets: On-demand secret generation for databases and services - [Dynamic Secrets](/docs/services/kms/platform/dynamic-secrets/overview): Learn how to generate secrets dynamically on-demand. - [PostgreSQL](/docs/services/kms/platform/dynamic-secrets/postgresql): Learn how to dynamically generate PostgreSQL database users. - [MySQL](/docs/services/kms/platform/dynamic-secrets/mysql): Learn how to dynamically generate MySQL Database user credentials. - [MS SQL](/docs/services/kms/platform/dynamic-secrets/mssql): Learn how to dynamically generate MS SQL database user credentials. - [Oracle](/docs/services/kms/platform/dynamic-secrets/oracle): Learn how to dynamically generate Oracle Database user credentials. - [Cassandra](/docs/services/kms/platform/dynamic-secrets/cassandra): Learn how to dynamically generate Cassandra database user credentials - [Redis](/docs/services/kms/platform/dynamic-secrets/redis): Learn how to dynamically generate Redis Database user credentials. - [AWS ElastiCache](/docs/services/kms/platform/dynamic-secrets/aws-elasticache): Learn how to dynamically generate AWS ElastiCache user credentials. - [AWS IAM](/docs/services/kms/platform/dynamic-secrets/aws-iam): Learn how to dynamically generate AWS IAM Users. - [GCP IAM](/docs/services/kms/platform/dynamic-secrets/gcp-iam): Learn how to dynamically generate GCP service account tokens. - [Azure Entra Id](/docs/services/kms/platform/dynamic-secrets/azure-entra-id): Learn how to dynamically generate Azure Entra Id user credentials. - [Azure SQL Database](/docs/services/kms/platform/dynamic-secrets/azure-sql-database): Learn how to dynamically generate Azure SQL Database user credentials. - [Elasticsearch](/docs/services/kms/platform/dynamic-secrets/elastic-search): Learn how to dynamically generate Elasticsearch user credentials. - [Mongo DB](/docs/services/kms/platform/dynamic-secrets/mongo-db): Learn how to dynamically generate Mongo DB Database user credentials. - [Mongo Atlas](/docs/services/kms/platform/dynamic-secrets/mongo-atlas): Learn how to dynamically generate Mongo Atlas Database user credentials. - [RabbitMQ](/docs/services/kms/platform/dynamic-secrets/rabbit-mq): Learn how to dynamically generate RabbitMQ user credentials. - [LDAP](/docs/services/kms/platform/dynamic-secrets/ldap): Learn how to dynamically generate user credentials via LDAP. - [SAP ASE](/docs/services/kms/platform/dynamic-secrets/sap-ase): Learn how to dynamically generate SAP ASE database account credentials. - [SAP HANA](/docs/services/kms/platform/dynamic-secrets/sap-hana): Learn how to dynamically generate SAP HANA database account credentials. - [Snowflake](/docs/services/kms/platform/dynamic-secrets/snowflake): Learn how to dynamically generate Snowflake user credentials. - [TOTP](/docs/services/kms/platform/dynamic-secrets/totp): Learn how to dynamically generate time-based one-time passwords. - [Vertica](/docs/services/kms/platform/dynamic-secrets/vertica): Learn how to dynamically generate Vertica database users. - [Couchbase](/docs/services/kms/platform/dynamic-secrets/couchbase): Learn how to dynamically generate Couchbase Database user credentials. - [GitHub](/docs/services/kms/platform/dynamic-secrets/github): Learn how to dynamically generate GitHub App tokens. - [Kubernetes](/docs/services/kms/platform/dynamic-secrets/kubernetes): Learn how to dynamically generate Kubernetes service account tokens. - Secret Rotation: Automated secret rotation for databases and services - [Secret Rotation](/docs/services/kms/platform/secret-rotation/overview): Learn how to set up automated secret rotation in Hanzo KMS. - [PostgreSQL Credentials Rotation](/docs/services/kms/platform/secret-rotation/postgres-credentials): Learn how to automatically rotate PostgreSQL credentials. - [MySQL Credentials Rotation](/docs/services/kms/platform/secret-rotation/mysql-credentials): Learn how to automatically rotate MySQL credentials. - [MySQL/MariaDB](/docs/services/kms/platform/secret-rotation/mysql): Learn how to automatically rotate MySQL/MariaDB user passwords. - [Microsoft SQL Server Credentials Rotation](/docs/services/kms/platform/secret-rotation/mssql-credentials): Learn how to automatically rotate Microsoft SQL Server credentials. - [MongoDB Credentials Rotation](/docs/services/kms/platform/secret-rotation/mongodb-credentials): Learn how to automatically rotate MongoDB credentials. - [Redis Credentials Rotation](/docs/services/kms/platform/secret-rotation/redis-credentials): Learn how to automatically rotate Redis credentials. - [OracleDB Credentials Rotation](/docs/services/kms/platform/secret-rotation/oracledb-credentials): Learn how to automatically rotate Oracle Database credentials. - [AWS IAM User](/docs/services/kms/platform/secret-rotation/aws-iam-user-secret): Learn how to automatically rotate Access Key Id and Secret Key of AWS IAM Users. - [Azure Client Secret](/docs/services/kms/platform/secret-rotation/azure-client-secret): Learn how to automatically rotate Azure Client Secrets. - [Databricks Service Principal Secret](/docs/services/kms/platform/secret-rotation/databricks-service-principal-secret): Learn how to automatically rotate Databricks Service Principal OAuth Secrets. - [DBT Service Token](/docs/services/kms/platform/secret-rotation/dbt-service-token): Learn how to automatically rotate DBT Service Tokens. - [LDAP Password Rotation](/docs/services/kms/platform/secret-rotation/ldap-password): Learn how to automatically rotate LDAP passwords. - [Auth0 Client Secret Rotation](/docs/services/kms/platform/secret-rotation/auth0-client-secret): Learn how to automatically rotate Auth0 Client Secrets. - [Okta Client Secret](/docs/services/kms/platform/secret-rotation/okta-client-secret): Learn how to automatically rotate Okta Client Secrets. - [OpenRouter API Key](/docs/services/kms/platform/secret-rotation/openrouter-api-key): Learn how to automatically rotate OpenRouter API keys. - [Twilio SendGrid](/docs/services/kms/platform/secret-rotation/sendgrid): Find out how to rotate Twilio SendGrid API keys. - [Unix/Linux Local Account Rotation](/docs/services/kms/platform/secret-rotation/unix-linux-local-account): Learn how to automatically rotate Unix/Linux local account passwords. - [Windows Local Account Rotation](/docs/services/kms/platform/secret-rotation/windows-local-account): Learn how to automatically rotate Windows local account passwords using SMB. - Secret Scanning: Detect leaked secrets in repositories - [Secret Scanning](/docs/services/kms/platform/secret-scanning/overview): Learn how to detect and respond to exposed secrets in code. - [Usage](/docs/services/kms/platform/secret-scanning/usage): Learn what is secret scanning and why it matters for building secure systems. - [GitHub Secret Scanning](/docs/services/kms/platform/secret-scanning/github): Learn how to configure secret scanning for GitHub. - [GitLab Secret Scanning](/docs/services/kms/platform/secret-scanning/gitlab): Learn how to configure secret scanning for GitLab. - [Bitbucket Secret Scanning](/docs/services/kms/platform/secret-scanning/bitbucket): Learn how to configure secret scanning for Bitbucket. - Concepts: Secret scanning concepts - [Secrets Scanning](/docs/services/kms/platform/secret-scanning/concepts/secret-scanning): Learn what is secret scanning and why it matters for building secure systems. - PKI: Public key infrastructure and certificate management - [Certificate Management](/docs/services/kms/platform/pki/overview): Manage Certificate Authorities and automate X.509 certificate lifecycle management. - [Approval Policies & Requests](/docs/services/kms/platform/pki/approvals): Learn how to configure approval workflows for certificate issuance. - [Kubernetes cert-manager](/docs/services/kms/platform/pki/k8s-cert-manager): Learn how to automatically provision and manage TLS certificates in Kubernetes using Hanzo KMS - [Subscribers](/docs/services/kms/platform/pki/subscribers): Learn how to manage PKI subscribers and issue X.509 certificates for them. - Concepts: PKI core concepts - [Certificate Management](/docs/services/kms/platform/pki/concepts/certificate-mgmt): Learn what is certificate management and why it matters for building secure systems. - [Certificate Lifecycle](/docs/services/kms/platform/pki/concepts/certificate-lifecycle): Learn what is the certificate lifecycle and how it works. - [Certificate Components](/docs/services/kms/platform/pki/concepts/certificate-components): Learn the main components for managing certificates with Hanzo KMS. - Certificate Authorities: Certificate authority configuration and management - [Overview](/docs/services/kms/platform/pki/ca/overview) - [Internal CA](/docs/services/kms/platform/pki/ca/private-ca): Learn how to create a Private CA hierarchy with Hanzo KMS. - [ACME-compatible CA](/docs/services/kms/platform/pki/ca/acme-ca): Learn how to connect Hanzo KMS to an ACME-compatible CA to issue certificates. - [Let's Encrypt](/docs/services/kms/platform/pki/ca/lets-encrypt): Learn how to connect Hanzo KMS to Let's Encrypt to issue certificates. - [AWS Private CA](/docs/services/kms/platform/pki/ca/aws-pca): Learn how to issue and manage certificates using AWS Private Certificate Authority (PCA) with Hanzo KMS. - [Microsoft AD CS](/docs/services/kms/platform/pki/ca/azure-adcs): Learn how to issue and manage certificates using Microsoft Active Directory Certificate Services (ADCS) with Hanzo KMS. - [DigiCert](/docs/services/kms/platform/pki/ca/digicert): Learn how to connect Hanzo KMS to DigiCert to issue certificates. - [Sectigo](/docs/services/kms/platform/pki/ca/sectigo): Learn how to connect Hanzo KMS to Sectigo to issue certificates via ACME. - [External CA](/docs/services/kms/platform/pki/ca/external-ca): Learn how to connect External Certificate Authorities with Hanzo KMS. - Certificates: Certificate management and policies - [Overview](/docs/services/kms/platform/pki/certificates/overview) - [Certificates](/docs/services/kms/platform/pki/certificates/certificates) - [Certificate Policies](/docs/services/kms/platform/pki/certificates/policies) - [Certificate Profiles](/docs/services/kms/platform/pki/certificates/profiles) - Enrollment Methods: Certificate enrollment and issuance methods - [Overview](/docs/services/kms/platform/pki/enrollment-methods/overview) - [Certificate Enrollment via ACME](/docs/services/kms/platform/pki/enrollment-methods/acme) - [Certificate Enrollment via EST](/docs/services/kms/platform/pki/enrollment-methods/est) - [Certificate Enrollment via SCEP](/docs/services/kms/platform/pki/enrollment-methods/scep) - [Certificate Enrollment via API](/docs/services/kms/platform/pki/enrollment-methods/api) - Certificate Syncs: Sync certificates to external services - [Overview](/docs/services/kms/platform/pki/certificate-syncs/overview): Learn how to sync certificates from KMS PKI to third-party services. - [AWS Certificate Manager](/docs/services/kms/platform/pki/certificate-syncs/aws-certificate-manager): Learn how to configure an AWS Certificate Manager Certificate Sync for KMS PKI. - [AWS Elastic Load Balancer](/docs/services/kms/platform/pki/certificate-syncs/aws-elastic-load-balancer): Learn how to configure an AWS Elastic Load Balancer Certificate Sync for KMS PKI. - [AWS Secrets Manager](/docs/services/kms/platform/pki/certificate-syncs/aws-secrets-manager): Learn how to configure an AWS Secrets Manager Certificate Sync for KMS PKI. - [Azure Key Vault](/docs/services/kms/platform/pki/certificate-syncs/azure-key-vault): Learn how to configure an Azure Key Vault Certificate Sync for KMS PKI. - [Chef](/docs/services/kms/platform/pki/certificate-syncs/chef): Learn how to configure a Chef Certificate Sync for KMS PKI. - [Cloudflare Custom Certificate](/docs/services/kms/platform/pki/certificate-syncs/cloudflare-custom-certificate): Learn how to configure a Cloudflare Custom Certificate Sync for KMS PKI. - Alerting: Certificate expiration and event alerting - [Alerting](/docs/services/kms/platform/pki/alerting/overview): Learn how to set up alerting for expiring certificates with Hanzo KMS - [Slack Alerts](/docs/services/kms/platform/pki/alerting/slack-alerts): Learn how to set up Slack notifications for PKI certificate alerts - [PagerDuty Alerts](/docs/services/kms/platform/pki/alerting/pagerduty-alerts): Learn how to set up PagerDuty notifications for PKI certificate alerts - [Webhook Alerts](/docs/services/kms/platform/pki/alerting/webhook-alerts): Learn how to set up webhook notifications for PKI certificate alerts - Discovery: Certificate discovery and scanning - [Overview](/docs/services/kms/platform/pki/discovery/overview): Learn how to discover certificates across your infrastructure with Hanzo KMS - [Network](/docs/services/kms/platform/pki/discovery/network): Learn how to configure a Network discovery job to find certificates across your infrastructure. - Guides: PKI how-to guides - [Set Up Certificate Approvals](/docs/services/kms/platform/pki/guides/certificate-approvals): Step-by-step guide to configuring certificate approval workflows. - [Request a Certificate via API](/docs/services/kms/platform/pki/guides/request-cert-api) - [Obtain a Certificate via ACME](/docs/services/kms/platform/pki/guides/request-cert-acme) - [Request a Certificate via the KMS Agent](/docs/services/kms/platform/pki/guides/request-cert-agent) - [Issue a Certificate with CSR](/docs/services/kms/platform/pki/guides/request-cert-csr): Learn how to issue certificates using a Certificate Signing Request (CSR) to maintain control of your private keys - Integration Guides: PKI integration with web servers and platforms - [Nginx](/docs/services/kms/platform/pki/integration-guides/nginx-certbot): Learn how to issue TLS certificates from Hanzo KMS using ACME enrollment on Nginx with Certbot - [Apache Server](/docs/services/kms/platform/pki/integration-guides/apache-certbot): Learn how to issue TLS certificates from Hanzo KMS using ACME enrollment on Apache Server with Certbot - [Tomcat](/docs/services/kms/platform/pki/integration-guides/tomcat-certbot): Learn how to issue TLS certificates from Hanzo KMS using ACME enrollment on Tomcat with Certbot - [JBoss/WildFly](/docs/services/kms/platform/pki/integration-guides/jboss-certbot): Learn how to issue TLS certificates from Hanzo KMS using ACME enrollment on JBoss/WildFly with Certbot - [Gloo Mesh](/docs/services/kms/platform/pki/integration-guides/gloo-mesh): Learn how to automatically provision and manage Istio intermediate CA certificates for Gloo Mesh using Hanzo KMS - [Windows Server](/docs/services/kms/platform/pki/integration-guides/windows-server-acme): Learn how to issue TLS certificates from Hanzo KMS using ACME enrollment on Windows Server with win-acme - KMS: Key management and encryption - [Key Management Service (KMS)](/docs/services/kms/platform/kms/overview): Learn how to manage and use cryptographic keys with Hanzo KMS. - [HSM Integration](/docs/services/kms/platform/kms/hsm-integration): Learn more about integrating an HSM with Hanzo KMS. - [KMIP Integration](/docs/services/kms/platform/kms/kmip): Learn more about integrating with Hanzo KMS using KMIP (Key Management Interoperability Protocol). - [Kubernetes Encryption with KMS](/docs/services/kms/platform/kms/kubernetes-encryption) - KMS Configuration: External KMS provider configuration - [Key Management Service (KMS) Configuration](/docs/services/kms/platform/kms-configuration/overview): Learn how to configure your project's encryption - [AWS Key Management Service](/docs/services/kms/platform/kms-configuration/aws-kms): Learn how to manage encryption using AWS KMS - [AWS CloudHSM](/docs/services/kms/platform/kms-configuration/aws-hsm): Learn how to manage encryption using AWS CloudHSM - [GCP Key Management Service](/docs/services/kms/platform/kms-configuration/gcp-kms): Learn how to manage encryption using GCP KMS - Gateways: KMS gateway deployment and security - [Gateway Overview](/docs/services/kms/platform/gateways/overview): How to access private network resources from Hanzo KMS - [Gateway Deployment](/docs/services/kms/platform/gateways/gateway-deployment): Complete guide to deploying KMS Gateways including network configuration and firewall requirements - [Security Architecture](/docs/services/kms/platform/gateways/security): Security model, tenant isolation, and best practices for KMS Gateways and Relays - Relay Deployment: Relay gateway deployment options - [Overview](/docs/services/kms/platform/gateways/relay-deployment/overview): How to deploy Hanzo KMS Relay Servers - [Terraform](/docs/services/kms/platform/gateways/relay-deployment/terraform): How to deploy Hanzo KMS Relay Servers using Terraform - External Migrations: Migrate secrets from other platforms - [External Migrations](/docs/services/kms/platform/external-migrations/overview): Learn how to migrate resources from third-party secrets management platforms to Hanzo KMS. - [Migrating from EnvKey to Hanzo KMS](/docs/services/kms/platform/external-migrations/envkey): Learn how to migrate secrets from EnvKey to Hanzo KMS. - [Migrating from Vault to Hanzo KMS](/docs/services/kms/platform/external-migrations/vault): Learn how to migrate resources from Vault to Hanzo KMS. - Admin Panel: Administration console and server management - [Overview](/docs/services/kms/platform/admin-panel/overview): Learn about Hanzo KMS's Admin Consoles - [Organization Admin Console](/docs/services/kms/platform/admin-panel/org-admin-console): View and manage resources across your organization - [Server Admin Console](/docs/services/kms/platform/admin-panel/server-admin): Configure and manage server related features - Agent Sentinel: AI agent access control and monitoring - [Agent Sentinel](/docs/services/kms/platform/agent-sentinel/overview): Manage MCP endpoints, connect MCP servers, and configure AI tools with secure governance. - [Activity Logs](/docs/services/kms/platform/agent-sentinel/activity-logs): Monitor and audit AI tool usage with detailed activity logs. - [MCP Endpoints](/docs/services/kms/platform/agent-sentinel/mcp-endpoints): Learn how to create and manage MCP endpoints for AI clients. - [MCP Servers](/docs/services/kms/platform/agent-sentinel/mcp-servers): Learn how to connect and manage MCP servers in Hanzo KMS. - Concepts: Agent Sentinel core concepts - [Model Context Protocol](/docs/services/kms/platform/agent-sentinel/concepts/mcp-overview): Learn what the Model Context Protocol is and how Hanzo KMS helps you manage it securely. - Audit Log Streams: Stream audit logs to external services - [Audit Log Streams](/docs/services/kms/platform/audit-log-streams/audit-log-streams): Learn how to stream Hanzo KMS Audit Logs to external logging providers. - [Stream to Non-HTTP providers](/docs/services/kms/platform/audit-log-streams/audit-log-streams-with-fluentbit): How to stream Hanzo KMS Audit Logs to Non-HTTP log providers - Privileged Access Management: Privileged access management for infrastructure - [Overview](/docs/services/kms/platform/pam/overview): Manage and secure access to critical infrastructure like databases and servers with policy-based controls and approvals. - [Architecture](/docs/services/kms/platform/pam/architecture): Learn about the architecture, components, and security model of KMS PAM. - Getting Started: Getting started with PAM - [Setup](/docs/services/kms/platform/pam/getting-started/setup): This guide provides a step-by-step walkthrough for configuring Hanzo KMS's Privileged Access Management (PAM). Learn how to deploy a gateway, define resources, and grant your team secure, audited access to critical infrastructure. - [PAM Account](/docs/services/kms/platform/pam/getting-started/accounts): Learn how to create and manage accounts in PAM to control access to resources like databases and servers. - Resources: PAM resource configuration - [SSH](/docs/services/kms/platform/pam/getting-started/resources/ssh): Learn how to configure SSH server access through KMS PAM with support for password, key-based, and certificate-based authentication. - [Kubernetes](/docs/services/kms/platform/pam/getting-started/resources/kubernetes): Learn how to configure Kubernetes cluster access through KMS PAM for secure, audited, and just-in-time access to your Kubernetes clusters. - [AWS IAM](/docs/services/kms/platform/pam/getting-started/resources/aws-iam): Learn how to configure AWS Management Console access through KMS PAM for secure, audited, and just-in-time access to AWS. - [Active Directory](/docs/services/kms/platform/pam/getting-started/resources/active-directory): Learn how to configure Active Directory access through KMS PAM for secure, audited management of your AD domain controllers and domain-joined resources. - [Redis](/docs/services/kms/platform/pam/getting-started/resources/redis): Learn how to configure Redis access through KMS PAM for secure, audited, and just-in-time access to your Redis instances. - [Windows Server](/docs/services/kms/platform/pam/getting-started/resources/windows-server): Learn how to configure Windows Server access through KMS PAM for secure, audited, and just-in-time access to your Windows servers via RDP. - Product Reference: PAM product reference documentation - [Approval Policies & Requests](/docs/services/kms/platform/pam/product-reference/access-policies): Learn how to configure approval workflows for PAM account access. - [Credential Rotation](/docs/services/kms/platform/pam/product-reference/credential-rotation): Learn how to automate credential rotation for your PAM resources. - [Session Recording](/docs/services/kms/platform/pam/product-reference/session-recording): Learn how Hanzo KMS records and stores session activity for auditing and monitoring. - [Auditing](/docs/services/kms/platform/pam/product-reference/auditing): Learn how Hanzo KMS audits all actions across your PAM project. - Web Access: Browser-based privileged access - [Web Access](/docs/services/kms/platform/pam/product-reference/web-access/overview): Access PAM-managed resources directly from your browser with an interactive terminal. - [PostgreSQL Web Access](/docs/services/kms/platform/pam/product-reference/web-access/postgresql): Run SQL queries against PostgreSQL databases directly from your browser. - Workflow Integrations: Chat and workflow tool integrations - [Slack Integration](/docs/services/kms/platform/workflow-integrations/slack-integration): Learn how to setup the Slack integration - [Microsoft Teams Integration](/docs/services/kms/platform/workflow-integrations/microsoft-teams-integration): Learn how to setup the Microsoft Teams integration - Integrations: Third-party integrations and connectors - [Framework Integrations](/docs/services/kms/integrations/framework-integrations): Browse and search through all available framework integrations for Hanzo KMS. - [User Authentication](/docs/services/kms/integrations/user-authentication): Browse and search through all available user authentication methods for Hanzo KMS. - [Machine Authentication](/docs/services/kms/integrations/machine-authentication): Browse and search through all available machine authentication methods for Hanzo KMS. - App Connections: Connect KMS to third-party applications - [Overview](/docs/services/kms/integrations/app-connections/overview): Learn how to manage and configure third-party app connections with Hanzo KMS. - [1Password Connection](/docs/services/kms/integrations/app-connections/1password): Learn how to configure a 1Password Connection for Hanzo KMS. - [Auth0 Connection](/docs/services/kms/integrations/app-connections/auth0): Learn how to configure an Auth0 Connection for Hanzo KMS. - [AWS Connection](/docs/services/kms/integrations/app-connections/aws): Learn how to configure an AWS Connection for Hanzo KMS. - [Azure ADCS Connection](/docs/services/kms/integrations/app-connections/azure-adcs): Learn how to configure an Azure ADCS Connection for Hanzo KMS certificate management. - [Azure App Configuration Connection](/docs/services/kms/integrations/app-connections/azure-app-configuration): Learn how to configure a Azure App Configuration Connection for Hanzo KMS. - [Azure Client Secrets Connection](/docs/services/kms/integrations/app-connections/azure-client-secrets): Learn how to configure an Azure Client Secrets Connection for Hanzo KMS. - [Azure DevOps Connection](/docs/services/kms/integrations/app-connections/azure-devops): Learn how to configure an Azure DevOps Connection for Hanzo KMS. - [Azure DNS Connection](/docs/services/kms/integrations/app-connections/azure-dns): Learn how to configure an Azure DNS Connection for Hanzo KMS. - [Azure Key Vault Connection](/docs/services/kms/integrations/app-connections/azure-key-vault): Learn how to configure a Azure Key Vault Connection for Hanzo KMS. - [Bitbucket Connection](/docs/services/kms/integrations/app-connections/bitbucket): Learn how to configure a Bitbucket Connection for Hanzo KMS. - [Camunda Connection](/docs/services/kms/integrations/app-connections/camunda): Learn how to configure a Camunda Connection for Hanzo KMS. - [Checkly Connection](/docs/services/kms/integrations/app-connections/checkly): Learn how to configure a Checkly Connection for Hanzo KMS. - [Chef Connection](/docs/services/kms/integrations/app-connections/chef): Learn how to configure a Chef Connection for Hanzo KMS. - [CircleCI Connection](/docs/services/kms/integrations/app-connections/circleci): Learn how to configure a CircleCI Connection for Hanzo KMS. - [Cloudflare Connection](/docs/services/kms/integrations/app-connections/cloudflare): Learn how to configure a Cloudflare Connection for Hanzo KMS. - [Databricks Connection](/docs/services/kms/integrations/app-connections/databricks): Learn how to configure a Databricks Connection for Hanzo KMS. - [DBT Connection](/docs/services/kms/integrations/app-connections/dbt): Learn how to configure a DBT Connection for Hanzo KMS. - [DigitalOcean Connection](/docs/services/kms/integrations/app-connections/digital-ocean): Learn how to configure a DigitalOcean Connection for Hanzo KMS. - [DNS Made Easy](/docs/services/kms/integrations/app-connections/dns-made-easy): Learn how to configure a DNS Made Easy Connection for Hanzo KMS. - [Fly.io Connection](/docs/services/kms/integrations/app-connections/flyio): Learn how to configure a Fly.io Connection for Hanzo KMS. - [GCP Connection](/docs/services/kms/integrations/app-connections/gcp): Learn how to configure a GCP Connection for Hanzo KMS. - [GitHub Connection](/docs/services/kms/integrations/app-connections/github): Learn how to configure a GitHub Connection for Hanzo KMS. - [GitHub Radar Connection](/docs/services/kms/integrations/app-connections/github-radar): Learn how to configure a GitHub Radar Connection for Hanzo KMS. - [GitLab Connection](/docs/services/kms/integrations/app-connections/gitlab): Learn how to configure a GitLab Connection for Hanzo KMS using OAuth or Access Token methods. - [external-secret-manager Connection](/docs/services/kms/integrations/app-connections/hashicorp-vault): Learn how to configure a external-secret-manager Connection for Hanzo KMS. - [Heroku Connection](/docs/services/kms/integrations/app-connections/heroku): Learn how to configure a Heroku Connection for Hanzo KMS using OAuth or Auth Token methods. - [Humanitec Connection](/docs/services/kms/integrations/app-connections/humanitec): Learn how to configure a Humanitec Connection for Hanzo KMS. - [Laravel Forge Connection](/docs/services/kms/integrations/app-connections/laravel-forge): Learn how to configure a Laravel Forge Connection for Hanzo KMS. - [LDAP Connection](/docs/services/kms/integrations/app-connections/ldap): Learn how to configure an LDAP Connection for Hanzo KMS. - [MongoDB Connection](/docs/services/kms/integrations/app-connections/mongodb): Learn how to configure a MongoDB Connection for Hanzo KMS. - [Microsoft SQL Server Connection](/docs/services/kms/integrations/app-connections/mssql): Learn how to configure a Microsoft SQL Server Connection for Hanzo KMS. - [MySQL Connection](/docs/services/kms/integrations/app-connections/mysql): Learn how to configure a MySQL Connection for Hanzo KMS. - [Netlify Connection](/docs/services/kms/integrations/app-connections/netlify): Learn how to configure a Netlify Connection for Hanzo KMS. - [Northflank Connection](/docs/services/kms/integrations/app-connections/northflank): Learn how to configure a Northflank Connection for Hanzo KMS. - [OCI Connection](/docs/services/kms/integrations/app-connections/oci): Learn how to configure an Oracle Cloud Infrastructure Connection for Hanzo KMS. - [Octopus Deploy Connection](/docs/services/kms/integrations/app-connections/octopus-deploy): Learn how to configure an Octopus Deploy Connection for Hanzo KMS. - [Okta Connection](/docs/services/kms/integrations/app-connections/okta): Learn how to configure an Okta Connection for Hanzo KMS. - [OpenRouter Connection](/docs/services/kms/integrations/app-connections/openrouter): Learn how to configure an OpenRouter (LLM router) connection for Hanzo KMS. - [OracleDB Connection](/docs/services/kms/integrations/app-connections/oracledb): Learn how to configure a Oracle Database Connection for Hanzo KMS. - [PostgreSQL Connection](/docs/services/kms/integrations/app-connections/postgres): Learn how to configure a PostgreSQL Connection for Hanzo KMS. - [Railway Connection](/docs/services/kms/integrations/app-connections/railway): Learn how to configure a Railway Connection for Hanzo KMS. - [Redis Connection](/docs/services/kms/integrations/app-connections/redis): Learn how to configure a Redis Connection for Hanzo KMS. - [Render Connection](/docs/services/kms/integrations/app-connections/render): Learn how to configure a Render Connection for Hanzo KMS. - [SMB](/docs/services/kms/integrations/app-connections/smb): Learn how to configure an SMB Connection for Hanzo KMS. - [SSH](/docs/services/kms/integrations/app-connections/ssh): Learn how to configure an SSH Connection for Hanzo KMS. - [Supabase Connection](/docs/services/kms/integrations/app-connections/supabase): Learn how to configure a Supabase Connection for Hanzo KMS. - [TeamCity Connection](/docs/services/kms/integrations/app-connections/teamcity): Learn how to configure a TeamCity Connection for Hanzo KMS. - [Terraform Cloud Connection](/docs/services/kms/integrations/app-connections/terraform-cloud): Learn how to configure a Terraform Cloud Connection for Hanzo KMS. - [Vercel Connection](/docs/services/kms/integrations/app-connections/vercel): Learn how to configure a Vercel Connection for Hanzo KMS. - [Windmill Connection](/docs/services/kms/integrations/app-connections/windmill): Learn how to configure a Windmill Connection for Hanzo KMS. - [Zabbix Connection](/docs/services/kms/integrations/app-connections/zabbix): Learn how to configure a Zabbix Connection for Hanzo KMS. - Secret Syncs: Sync secrets to external services - [Overview](/docs/services/kms/integrations/secret-syncs/overview): Learn how to sync secrets to third-party services with Hanzo KMS. - [1Password Sync](/docs/services/kms/integrations/secret-syncs/1password): Learn how to configure a 1Password Sync for Hanzo KMS. - [AWS Parameter Store Sync](/docs/services/kms/integrations/secret-syncs/aws-parameter-store): Learn how to configure an AWS Parameter Store Sync for Hanzo KMS. - [AWS Secrets Manager Sync](/docs/services/kms/integrations/secret-syncs/aws-secrets-manager): Learn how to configure an AWS Secrets Manager Sync for Hanzo KMS. - [Azure App Configuration Sync](/docs/services/kms/integrations/secret-syncs/azure-app-configuration): Learn how to configure an Azure App Configuration Sync for Hanzo KMS. - [Azure DevOps Sync](/docs/services/kms/integrations/secret-syncs/azure-devops): Learn how to configure a Azure DevOps Sync for Hanzo KMS. - [Azure Key Vault Sync](/docs/services/kms/integrations/secret-syncs/azure-key-vault): Learn how to configure a Azure Key Vault Sync for Hanzo KMS. - [Bitbucket Sync](/docs/services/kms/integrations/secret-syncs/bitbucket): Learn how to configure a Bitbucket Sync for Hanzo KMS. - [Camunda Sync](/docs/services/kms/integrations/secret-syncs/camunda): Learn how to configure a Camunda Sync for Hanzo KMS. - [Checkly Sync](/docs/services/kms/integrations/secret-syncs/checkly): Learn how to configure a Checkly Sync for Hanzo KMS. - [Chef Sync](/docs/services/kms/integrations/secret-syncs/chef): Learn how to configure a Chef Sync for Hanzo KMS. - [CircleCI Sync](/docs/services/kms/integrations/secret-syncs/circleci): Learn how to configure a CircleCI Sync for Hanzo KMS. - [Cloudflare Pages Sync](/docs/services/kms/integrations/secret-syncs/cloudflare-pages): Learn how to configure a Cloudflare Pages Sync for Hanzo KMS. - [Cloudflare Workers Sync](/docs/services/kms/integrations/secret-syncs/cloudflare-workers): Learn how to configure a Cloudflare Workers Sync for Hanzo KMS. - [Databricks Sync](/docs/services/kms/integrations/secret-syncs/databricks): Learn how to configure a Databricks Sync for Hanzo KMS. - [DigitalOcean App Platform Sync](/docs/services/kms/integrations/secret-syncs/digital-ocean-app-platform): Learn how to configure a DigitalOcean App Platform Sync for Hanzo KMS. - [Fly.io Sync](/docs/services/kms/integrations/secret-syncs/flyio): Learn how to configure a Fly.io Sync for Hanzo KMS. - [GCP Secret Manager Sync](/docs/services/kms/integrations/secret-syncs/gcp-secret-manager): Learn how to configure a GCP Secret Manager Sync for Hanzo KMS. - [GitHub Sync](/docs/services/kms/integrations/secret-syncs/github): Learn how to configure a GitHub Sync for Hanzo KMS. - [GitLab Sync](/docs/services/kms/integrations/secret-syncs/gitlab): Learn how to configure a GitLab Sync for Hanzo KMS. - [external-secret-manager Sync](/docs/services/kms/integrations/secret-syncs/hashicorp-vault): Learn how to configure a external-secret-manager Sync for Hanzo KMS. - [Heroku Sync](/docs/services/kms/integrations/secret-syncs/heroku): Learn how to configure a Heroku Sync for Hanzo KMS. - [Humanitec Sync](/docs/services/kms/integrations/secret-syncs/humanitec): Learn how to configure a Humanitec Sync for Hanzo KMS. - [Laravel Forge Sync](/docs/services/kms/integrations/secret-syncs/laravel-forge): Learn how to configure a Laravel Forge Sync for Hanzo KMS. - [Netlify Sync](/docs/services/kms/integrations/secret-syncs/netlify): Learn how to configure a Netlify Sync for Hanzo KMS. - [Northflank Sync](/docs/services/kms/integrations/secret-syncs/northflank): Learn how to configure a Northflank Sync for Hanzo KMS. - [OCI Vault Sync](/docs/services/kms/integrations/secret-syncs/oci-vault): Learn how to configure an Oracle Cloud Infrastructure Vault Sync for Hanzo KMS. - [Octopus Deploy Sync](/docs/services/kms/integrations/secret-syncs/octopus-deploy): Learn how to configure an Octopus Deploy Sync for Hanzo KMS. - [Railway Sync](/docs/services/kms/integrations/secret-syncs/railway): Learn how to configure a Railway Sync for Hanzo KMS. - [Render Sync](/docs/services/kms/integrations/secret-syncs/render): Learn how to configure a Render Sync for Hanzo KMS. - [Supabase Sync](/docs/services/kms/integrations/secret-syncs/supabase): Learn how to configure a Supabase Sync for Hanzo KMS. - [TeamCity Sync](/docs/services/kms/integrations/secret-syncs/teamcity): Learn how to configure a TeamCity Sync for Hanzo KMS. - [Terraform Cloud Sync](/docs/services/kms/integrations/secret-syncs/terraform-cloud): Learn how to configure a Terraform Cloud Sync for Hanzo KMS. - [Vercel Sync](/docs/services/kms/integrations/secret-syncs/vercel): Learn how to configure a Vercel Sync for Hanzo KMS. - [Windmill Sync](/docs/services/kms/integrations/secret-syncs/windmill): Learn how to configure a Windmill Sync for Hanzo KMS. - [Zabbix Sync](/docs/services/kms/integrations/secret-syncs/zabbix): Learn how to configure a Zabbix Sync for Hanzo KMS. - [Dynamic Secrets](/docs/services/kms/integrations/dynamic-secrets): Browse and search through all available dynamic secrets for Hanzo KMS. - [Secret Rotations](/docs/services/kms/integrations/secret-rotations): Browse and search through all available secret rotations for Hanzo KMS. - Frameworks: Framework-specific integrations - [React](/docs/services/kms/integrations/frameworks/react): How to use Hanzo KMS to inject environment variables and secrets into a React app. - [Next.js](/docs/services/kms/integrations/frameworks/nextjs): How to use Hanzo KMS to inject environment variables and secrets into a Next.js app. - [Nuxt](/docs/services/kms/integrations/frameworks/nuxt): How to use Hanzo KMS to inject environment variables and secrets into a Nuxt app. - [Vue](/docs/services/kms/integrations/frameworks/vue): How to use Hanzo KMS to inject environment variables and secrets into a Vue.js app. - [Express, Fastify, Koa](/docs/services/kms/integrations/frameworks/express): How to use Hanzo KMS to inject environment variables and secrets into an Express app. - [NestJS](/docs/services/kms/integrations/frameworks/nestjs): How to use Hanzo KMS to inject environment variables and secrets into a NestJS app. - [SvelteKit](/docs/services/kms/integrations/frameworks/sveltekit): How to use Hanzo KMS to inject environment variables and secrets into a SvelteKit app. - [Remix](/docs/services/kms/integrations/frameworks/remix): How to use Hanzo KMS to inject environment variables and secrets into a Remix app. - [Gatsby](/docs/services/kms/integrations/frameworks/gatsby): How to use Hanzo KMS to inject environment variables and secrets into a Gatsby app. - [Vite](/docs/services/kms/integrations/frameworks/vite): How to use Hanzo KMS to inject environment variables and secrets into a Vite app. - [Bun](/docs/services/kms/integrations/frameworks/bun): How to use Hanzo KMS to inject environment variables and secrets into a Bun app. - [Django](/docs/services/kms/integrations/frameworks/django): How to use Hanzo KMS to inject environment variables and secrets into a Django app. - [Flask](/docs/services/kms/integrations/frameworks/flask): How to use Hanzo KMS to inject environment variables and secrets into a Flask app. - [Ruby on Rails](/docs/services/kms/integrations/frameworks/rails): How to use Hanzo KMS to inject environment variables and secrets into a Ruby on Rails app. - [Laravel](/docs/services/kms/integrations/frameworks/laravel): How to use Hanzo KMS to inject environment variables and secrets into a Laravel app. - [Fiber](/docs/services/kms/integrations/frameworks/fiber): How to use Hanzo KMS to inject environment variables and secrets into a Fiber app. - [.NET](/docs/services/kms/integrations/frameworks/dotnet): How to use Hanzo KMS to inject environment variables and secrets into a .NET app. - [Spring Boot with Maven](/docs/services/kms/integrations/frameworks/spring-boot-maven): How to use Hanzo KMS to inject environment variables into Java Spring Boot - [Terraform](/docs/services/kms/integrations/frameworks/terraform): Learn how to fetch secrets from Hanzo KMS with Terraform using both traditional data sources and ephemeral resources - [Pulumi](/docs/services/kms/integrations/frameworks/pulumi): Using Hanzo KMS with Pulumi via the Terraform Bridge - [Packer](/docs/services/kms/integrations/frameworks/packer): Learn how to fetch secrets from Hanzo KMS with Packer using a data source - [AB Initio](/docs/services/kms/integrations/frameworks/ab-initio): How to use Hanzo KMS secrets in AB Initio. - Build Tools: Build tool integrations - [Gradle](/docs/services/kms/integrations/build-tools/gradle): How to use Hanzo KMS to inject environment variables with Gradle - CI/CD: Continuous integration and deployment integrations - [GitHub Actions](/docs/services/kms/integrations/cicd/githubactions): How to inject secrets from Hanzo KMS into GitHub Actions workflows using OIDC authentication - [GitLab](/docs/services/kms/integrations/cicd/gitlab): How to sync secrets from Hanzo KMS to GitLab - [Bitbucket](/docs/services/kms/integrations/cicd/bitbucket): How to sync secrets from Hanzo KMS to Bitbucket - [Jenkins Plugin](/docs/services/kms/integrations/cicd/jenkins): How to effectively and securely manage secrets in Jenkins using Hanzo KMS - [AWS Amplify](/docs/services/kms/integrations/cicd/aws-amplify): Learn how to sync secrets from Hanzo KMS to AWS Amplify. - Platforms: Platform and infrastructure integrations - [Docker](/docs/services/kms/integrations/platforms/docker-intro): Learn how to feed secrets from Hanzo KMS into your Docker application. - [Docker Entrypoint](/docs/services/kms/integrations/platforms/docker): Learn how to use Hanzo KMS to inject environment variables into a Docker container. - [Docker Compose](/docs/services/kms/integrations/platforms/docker-compose): Find out how to use Hanzo KMS to inject environment variables into services defined in your Docker Compose file. - [Docker Run](/docs/services/kms/integrations/platforms/docker-pass-envs): Learn how to pass secrets to your docker container at run time. - [Docker Swarm](/docs/services/kms/integrations/platforms/docker-swarm-with-agent): Learn how to manage secrets in Docker Swarm services. - [Kubernetes CSI](/docs/services/kms/integrations/platforms/kubernetes-csi): How to use the Hanzo KMS Kubernetes CSI provider to inject secrets directly into Kubernetes pods. - [Kubernetes Agent Injector](/docs/services/kms/integrations/platforms/kubernetes-injector): How to use the Hanzo KMS Kubernetes Agent Injector to inject secrets directly into Kubernetes pods. - Kubernetes: Kubernetes operator and CRDs - [Kubernetes Operator](/docs/services/kms/integrations/platforms/kubernetes/overview): How to use Hanzo KMS to inject, push, and manage secrets within Kubernetes clusters - AWS: AWS platform integrations - [AWS Lambda](/docs/services/kms/integrations/platforms/aws/lambda): How to use Hanzo KMS secrets in AWS Lambda - [Amazon ECS](/docs/services/kms/integrations/platforms/ecs-with-agent): Learn how to deliver secrets to Amazon Elastic Container Service. - [KMS Agent](/docs/services/kms/integrations/platforms/certificate-agent): Learn how to use KMS CLI Agent to manage certificates automatically. - [Ansible](/docs/services/kms/integrations/platforms/ansible): Learn how to use Hanzo KMS for secret management in Ansible. - [Apache Airflow](/docs/services/kms/integrations/platforms/apache-airflow): Learn how to use Hanzo KMS as your custom secrets backend in Apache Airflow. - [PM2](/docs/services/kms/integrations/platforms/pm2): How to use Hanzo KMS to inject environment variables and secrets with PM2 into a Node.js app - External: External service integrations - [Backstage Hanzo KMS Plugin](/docs/services/kms/integrations/external/backstage): A powerful plugin that integrates Hanzo KMS secrets management into your Backstage developer portal. - SDKs: Client SDK libraries - [SDKs](/docs/services/kms/sdks/overview) - Languages: Language-specific SDK documentation - [Hanzo KMS Node.js SDK](/docs/services/kms/sdks/languages/node) - [Hanzo KMS Python SDK](/docs/services/kms/sdks/languages/python) - [Hanzo KMS Go SDK](/docs/services/kms/sdks/languages/go) - [Hanzo KMS Java SDK](/docs/services/kms/sdks/languages/java) - [Hanzo KMS Ruby SDK](/docs/services/kms/sdks/languages/ruby) - [Hanzo KMS .NET SDK](/docs/services/kms/sdks/languages/dotnet) - [Hanzo KMS PHP SDK](/docs/services/kms/sdks/languages/php) - [Hanzo KMS Rust SDK](/docs/services/kms/sdks/languages/rust) - [Hanzo KMS C++ SDK](/docs/services/kms/sdks/languages/cpp) - CLI: KMS command-line interface - [Install](/docs/services/kms/cli/overview): Hanzo KMS's CLI is one of the best ways to manage environments and secrets. Install it here - [Quickstart](/docs/services/kms/cli/usage): Manage secrets with KMS CLI - [Project config file](/docs/services/kms/cli/project-config): Project config file & customization options - [Secret scanning](/docs/services/kms/cli/scanning-overview): Scan and prevent secret leaks in your code base - [FAQ](/docs/services/kms/cli/faq): Frequently Asked Questions about KMS CLI - Commands: CLI command reference - [Commands](/docs/services/kms/cli/commands/commands): KMS CLI command overview - [kms bootstrap](/docs/services/kms/cli/commands/bootstrap): Automate the initial setup of a new Hanzo KMS instance for headless deployment and infrastructure-as-code workflows - [kms dynamic-secrets](/docs/services/kms/cli/commands/dynamic-secrets): Perform dynamic secret operations directly with the CLI - [kms export](/docs/services/kms/cli/commands/export): Export Hanzo KMS secrets from CLI into different file formats - [kms gateway](/docs/services/kms/cli/commands/gateway): Run the Hanzo KMS gateway or manage its systemd service - [kms init](/docs/services/kms/cli/commands/init): Switch between Hanzo KMS projects within CLI - [kms login](/docs/services/kms/cli/commands/login): Login into Hanzo KMS from the CLI - [kms relay](/docs/services/kms/cli/commands/relay): Relay-related commands for Hanzo KMS - [kms reset](/docs/services/kms/cli/commands/reset): Reset Hanzo KMS - [kms run](/docs/services/kms/cli/commands/run): The command that injects your secrets into local environment - [scan](/docs/services/kms/cli/commands/scan): Scan git history, directories, and files for secrets - [scan git-changes](/docs/services/kms/cli/commands/scan-git-changes): Scan for secrets in your uncommitted code - [scan install](/docs/services/kms/cli/commands/scan-install): Add various scanning tools seamlessly into your development lifecycle - [kms secrets](/docs/services/kms/cli/commands/secrets): Perform CRUD operations with Hanzo KMS secrets - [kms service-token](/docs/services/kms/cli/commands/service-token): Manage Hanzo KMS service tokens - [kms ssh](/docs/services/kms/cli/commands/ssh): Generate SSH credentials with the CLI - [kms token](/docs/services/kms/cli/commands/token): Manage your Hanzo KMS identity access tokens - [kms user](/docs/services/kms/cli/commands/user): Manage logged in users - [kms vault](/docs/services/kms/cli/commands/vault): Change the vault type in Hanzo KMS - Guides: Practical guides and tutorials - [Introduction](/docs/services/kms/guides/introduction) - [Secret Management in Development Environments](/docs/services/kms/guides/local-development): Learn how to manage secrets in local development environments. - [Node](/docs/services/kms/guides/node) - [Python](/docs/services/kms/guides/python) - [Next.js + Vercel](/docs/services/kms/guides/nextjs-vercel) - [Managing Secrets With Kubernetes Operator](/docs/services/kms/guides/kubernetes-operator): How to use the Hanzo KMS Kubernetes Operator to Push Secrets, Pull Secrets, and Generate Dynamic Secrets within your clusters. - [Microsoft Power Apps](/docs/services/kms/guides/microsoft-power-apps): Learn how to manage secrets in Microsoft Power Apps with Hanzo KMS. - [Hanzo KMS Organizational Structure Blueprint](/docs/services/kms/guides/organization-structure): Learn how to structure your projects, secrets, and other resources within Hanzo KMS. - [Centralized vs. Self-Service Governance](/docs/services/kms/guides/governance-models): Learn how to structure Hanzo KMS for centralized platform administration or team self-service autonomy - Internals: Internal architecture and implementation details - [Overview](/docs/services/kms/internals/overview): Read how Hanzo KMS works under the hood. - [Security](/docs/services/kms/internals/security): Hanzo KMS's security model includes many considerations and initiatives. - [Service tokens](/docs/services/kms/internals/service-tokens): Understanding service tokens and their best practices. - [Machine identities](/docs/services/kms/internals/service-tokens-new): Understanding machine identities and their best practices - Architecture: System architecture overview - [Components](/docs/services/kms/internals/architecture/components): Understand Hanzo KMS's core architectural components and how they work together. - [Hanzo KMS Cloud](/docs/services/kms/internals/architecture/cloud): Architecture overview of Hanzo KMS's US and EU cloud deployments - Permissions: Permission system and access control internals - [Overview](/docs/services/kms/internals/permissions/overview): Hanzo KMS's permissions system provides granular access control. - [Organization Permissions](/docs/services/kms/internals/permissions/organization-permissions): Comprehensive guide to Hanzo KMS's organization-level permissions - [Project Permissions](/docs/services/kms/internals/permissions/project-permissions): Comprehensive guide to Hanzo KMS's project-level permissions - [Migration Guide](/docs/services/kms/internals/permissions/migration): Guide for migrating permissions in Hanzo KMS - Self-Hosting: Deploy and manage your own KMS instance - [Overview](/docs/services/kms/self-hosting/overview): Learn how to self-host Hanzo KMS on your own infrastructure. - [Hanzo KMS Enterprise](/docs/services/kms/self-hosting/ee): Find out how to activate Hanzo KMS Enterprise edition (EE) features. - [FAQ](/docs/services/kms/self-hosting/faq): Frequently Asked Questions about self-hosting Hanzo KMS. - Configuration: Environment variables and requirements - [Hardware requirements](/docs/services/kms/self-hosting/configuration/requirements): Find out the minimal requirements for operating Hanzo KMS. - [Environment Variables](/docs/services/kms/self-hosting/configuration/envars): Read how to configure environment variables for self-hosted Hanzo KMS. - Deployment Options: Deployment methods and platforms - [Docker Compose](/docs/services/kms/self-hosting/deployment-options/docker-compose): Deploy Hanzo KMS using Docker Compose for development, testing, or small-scale production environments. - [Kubernetes via Helm Chart](/docs/services/kms/self-hosting/deployment-options/kubernetes-helm): Learn how to deploy Hanzo KMS on Kubernetes using our official Helm chart. - [AWS (ECS with Fargate)](/docs/services/kms/self-hosting/deployment-options/aws-native): Deploy Hanzo KMS on AWS using ECS Fargate, RDS, ElastiCache, and ALB. - [GCP (GKE with Cloud SQL & Memorystore)](/docs/services/kms/self-hosting/deployment-options/gcp-native): Deploy Hanzo KMS securely on Google Cloud Platform using GKE, Cloud SQL, and Memorystore. - [Docker Swarm](/docs/services/kms/self-hosting/deployment-options/docker-swarm): How to self-host Hanzo KMS with Docker Swarm (HA). - [Upgrading](/docs/services/kms/self-hosting/deployment-options/linux-upgrade): How to upgrade Hanzo KMS deployment using linux package - Native: Native OS deployment - Linux Package: Linux package installation and configuration - [Installation](/docs/services/kms/self-hosting/deployment-options/native/linux-package/installation): Learn how to deploy Hanzo KMS using the Linux package - [Configurations](/docs/services/kms/self-hosting/deployment-options/native/linux-package/commands-configuration): Learn how to configure and manage the Hanzo KMS Linux package - Guides: Self-hosting operational guides - [Programmatic Provisioning](/docs/services/kms/self-hosting/guides/automated-bootstrapping): Learn how to provision and configure Hanzo KMS instances programmatically without UI interaction - [Production Hardening](/docs/services/kms/self-hosting/guides/production-hardening): Security hardening recommendations for production Hanzo KMS deployments - [Replication](/docs/services/kms/self-hosting/guides/replication): Learn how Hanzo KMS supports multi-region replication - [Migrate Mongo to Postgres](/docs/services/kms/self-hosting/guides/mongo-to-postgres): Learn how to migrate Hanzo KMS from MongoDB to PostgreSQL. - [Monitoring and Telemetry Setup](/docs/services/kms/self-hosting/guides/monitoring-telemetry): Learn how to set up monitoring and telemetry for your self-hosted Hanzo KMS instance using Grafana, Prometheus, and OpenTelemetry. - [CDN Caching for Static Assets](/docs/services/kms/self-hosting/guides/cdn-caching): How to set up CDN caching to prevent version skew issues during deployments - [Adding Custom Certificates](/docs/services/kms/self-hosting/guides/custom-certificates): Learn how to configure Hanzo KMS with custom certificates - Reference Architectures: Production deployment architecture examples - [AWS ECS (HA)](/docs/services/kms/self-hosting/reference-architectures/aws-ecs): Reference architecture for self-hosting Hanzo KMS on AWS ECS - [Google Cloud Run](/docs/services/kms/self-hosting/reference-architectures/google-cloud-run): Reference architecture for self-hosting Hanzo KMS on Google Cloud Run. - [Linux (HA)](/docs/services/kms/self-hosting/reference-architectures/linux-deployment-ha): Hanzo KMS High Availability Deployment architecture for Linux - [Kubernetes (HA)](/docs/services/kms/self-hosting/reference-architectures/on-prem-k8s-ha): Reference architecture for self-hosting Hanzo KMS on Kubernetes (HA) - Contributing: How to contribute to Hanzo KMS - Getting Started: Getting started with contributing - [Overview](/docs/services/kms/contributing/getting-started/overview): Contributing to the Hanzo KMS ecosystem. - [Code of Conduct](/docs/services/kms/contributing/getting-started/code-of-conduct): What you should know before contributing to Hanzo KMS? - [Pull requests](/docs/services/kms/contributing/getting-started/pull-requests): This guide walks through the code submission process for Hanzo KMS. - Platform: Contributing to the KMS platform - [Local development](/docs/services/kms/contributing/platform/developing): This guide will help you set up and run the Hanzo KMS platform in local development. - Backend: Backend development guide - [Backend folder structure](/docs/services/kms/contributing/platform/backend/folder-structure) - [Backend development guide](/docs/services/kms/contributing/platform/backend/how-to-create-a-feature) - Setup: Network and infrastructure setup - [Networking](/docs/services/kms/setup/networking): Network configuration details for Hanzo KMS Cloud - Hanzo MPC: Multi-Party Computation infrastructure for enterprise digital asset custody with blockchain-native consensus - [Hanzo MPC](/docs/services/mpc): Threshold multi-party signing for digital asset custody — distributed key generation, t-of-n signing, and proactive share refresh with post-quantum consensus. - [Consensus](/docs/services/mpc/consensus): Private BFT blockchain with dual-certificate Ed25519 + ML-DSA-65 finality for MPC cluster state management - [Protocols](/docs/services/mpc/protocols): Deep dive into the 8 cryptographic protocols powering Hanzo MPC - [API Reference](/docs/services/mpc/api): REST API reference for the Hanzo MPC custody service - [Deployment](/docs/services/mpc/deployment): Deploy Hanzo MPC with Helm, Docker, or Kubernetes - [Hanzo Guard](/docs/services/guard): LLM I/O sanitization -- PII redaction, prompt injection detection, content filtering, rate limiting, audit logging - [Hanzo Zero Trust](/docs/services/zt): Programmable zero-trust networking for AI infrastructure with identity-based access control, mTLS overlay networks, and post-quantum cryptography. - **Backend Services** - [Hanzo Base](/docs/services/base): Backend-as-a-service with an auto-generated REST API, IAM-native auth, realtime, file storage, durable tasks, and per-tenant encrypted storage - Hanzo ORM: Generics-based ORM for Go with type-safe models, auto-serialization, and multi-backend support. - [Hanzo ORM](/docs/services/orm): Generics-based ORM for Go with type-safe Model[T], auto-registration, auto-serialization, and multi-backend support. - [Models](/docs/services/orm/models): Define type-safe models with the Model[T] generic mixin. - [Queries](/docs/services/orm/queries): Type-safe query builder with filters, ordering, and pagination. - [Lifecycle Hooks](/docs/services/orm/hooks): Run custom logic before and after CRUD operations. - [Auto-Serialization](/docs/services/orm/serialization): Automatically marshal complex fields to JSON strings for storage. - [Caching](/docs/services/orm/caching): Read-through KV cache with memory LRU and Redis/Valkey backends. - [Validation](/docs/services/orm/validation): Struct field validation with the orm/val package. - [Database Drivers](/docs/services/orm/drivers): SQLite, ZAP binary protocol (PostgreSQL, MongoDB, Redis, ClickHouse), and custom driver support. - [Hanzo DB](/docs/services/db): Serverless PostgreSQL with pgvector, auto-scaling, instant branching, connection pooling, and point-in-time recovery. - [Hanzo KV](/docs/services/kv): Redis/Valkey-compatible in-memory key-value store with pub/sub, streams, Lua scripting, and cluster mode. - [Hanzo S3](/docs/services/s3): S3-compatible object storage for AI infrastructure - [Hanzo MQ](/docs/services/mq): High-performance message queue and job processing built on Hanzo KV (Redis Streams) with reliable delivery, priority queues, and dead letter support. - [Hanzo Stream](/docs/services/stream): Kafka-compatible streaming gateway built on Hanzo PubSub - [Hanzo PubSub](/docs/services/pubsub): High-performance publish/subscribe messaging with persistent streaming, key-value store, and object storage - [Hanzo Functions](/docs/services/functions): Serverless compute platform for event-driven functions with auto-scaling, scale-to-zero, and deep platform integration. - [Hanzo Edge](/docs/services/edge): On-device AI inference -- run Zen models and any GGUF model locally on macOS, Linux, iOS, Android, Web (WASM), and embedded devices with zero cloud dependency. - **Data & Observability** - [Hanzo Analytics](/docs/services/analytics): Usage, cost, and performance analytics for Hanzo services - Insights: Behavioral analytics, feature flags, session recording, and A/B testing - [Hanzo Insights](/docs/services/insights): Self-hosted behavioral analytics platform with feature flags, session recording, A/B testing, and product analytics. - [Quickstart](/docs/services/insights/quickstart): Install the Hanzo Insights SDK and send your first event in under 2 minutes. - [SDKs](/docs/services/insights/sdks): Client libraries for Hanzo Insights across all major platforms. - [Feature Flags](/docs/services/insights/feature-flags): Gradual rollouts, multivariate flags, and targeted feature delivery with Hanzo Insights. - [Session Recording](/docs/services/insights/session-recording): Replay user sessions with full privacy controls using Hanzo Insights session recording. - [Experiments](/docs/services/insights/experiments): A/B testing and experimentation with Hanzo Insights — statistical significance, holdout groups, and automatic winner detection. - [Custom Events](/docs/services/insights/events): Track domain-specific events with Hanzo Insights — naming conventions, properties, and best practices. - [Self-Hosting](/docs/services/insights/self-hosting): Deploy Hanzo Insights on your own infrastructure with Docker, Kubernetes, or Helm. - [Hanzo O11y](/docs/services/o11y): Full-stack observability platform — Prometheus metrics, Grafana dashboards, OpenTelemetry distributed tracing, log aggregation, alerting, and SLO management for Hanzo infrastructure and applications. - Hanzo Status - [Hanzo Status](/docs/services/status): White-label status monitoring with real-time health checks, response time tracking, and incident management - [Configuration](/docs/services/status/configuration): Complete configuration reference for Hanzo Status - [Deployment](/docs/services/status/deployment): Deploy Hanzo Status to Kubernetes, Docker, or bare metal - [Hanzo DNS](/docs/services/dns): Authoritative DNS management with Cloudflare integration, automatic TLS certificates, GeoDNS routing, and DNSSEC across all Hanzo domains. - [Hanzo Registry](/docs/services/registry): OCI-compliant container and model artifact registry with vulnerability scanning, image signing, multi-arch builds, and pull-through caching. - [Hanzo Visor](/docs/services/visor): VM and container runtime for AI workloads with GPU passthrough, live migration, snapshot/restore, and Kubernetes CRI integration. - **Commerce & Billing** - Commerce - **Getting Started** - [Hanzo Commerce](/docs/services/commerce): E-commerce platform and payment infrastructure - [Quick Start](/docs/services/commerce/quickstart): Get started with Hanzo Commerce in minutes - **Products** - [Products](/docs/services/commerce/products): Product catalog management - [Subscriptions](/docs/services/commerce/subscriptions): Recurring billing and usage-based pricing - **Payments** - [Payments](/docs/services/commerce/payments): Payment processing and providers - [Webhooks](/docs/services/commerce/webhooks): Real-time event notifications - **Reference** - [API Reference](/docs/services/commerce/api): Commerce REST API endpoints - [Configuration](/docs/services/commerce/configuration): Environment variables and deployment options - [Pricing API](/docs/services/pricing): Unified pricing API for AI models, cloud plans, GPU tiers, and subscriptions - [Hanzo Sign](/docs/services/sign): Document signing and e-signature platform - [Hanzo Dataroom](/docs/services/dataroom): Secure document sharing with analytics and access controls - [Hanzo Cap Table](/docs/services/captable): Equity management and cap table platform - [Hanzo Referral](/docs/services/referral): Earn credits and revenue share by referring developers to the Hanzo platform. - **Event Catalogs** - [Commerce Event Catalog](/docs/services/commerce-events): Reference for all commerce events published to NATS/JetStream, including GA4 and Facebook CAPI normalization. - [Insights Event Catalog](/docs/services/insights-events): Reference for @hanzo/insights event tracking — standard events, custom events, feature flags, and session recording. - **Web3 Infrastructure** - Web3: Blockchain infrastructure powered by Bootnode - [Web3 Infrastructure](/docs/services/web3): Blockchain infrastructure powered by Bootnode — multi-chain RPC, token APIs, fleet management, and full observability. - [Multi-chain RPC](/docs/services/web3/rpc): JSON-RPC and WebSocket endpoints for 30+ blockchains via a unified API. - [Token & NFT APIs](/docs/services/web3/tokens): Indexed ERC-20 balances, NFT metadata, transfer history, and collection data. - [Smart Wallets](/docs/services/web3/wallets): ERC-4337 account abstraction with gas sponsorship and batched transactions. - [Fleet Management](/docs/services/web3/fleets): Deploy, scale, and manage validator node fleets across blockchain networks. - [Infrastructure Services](/docs/services/web3/services): Deploy block explorers, bridges, DEXs, multisig wallets, faucets, and more per-network. - [Observability](/docs/services/web3/observability): Health checks, metrics, alerts, logs, and service maps via ClickHouse, Loki, and Grafana. - [ZAP Protocol](/docs/services/web3/zap): Cap'n Proto binary RPC for AI agents to control blockchain infrastructure. - **Infrastructure Stack** - [Hanzo Ingress](/docs/services/ingress): Cloud-native L7 reverse proxy and load balancer for Hanzo AI infrastructure -- Kubernetes-native with automatic TLS, dynamic configuration, and zero-downtime reloads. - [API](/docs/api): The REST API reference for every Hanzo Cloud service -- one base URL, one bearer key, at api.hanzo.ai/v1. - API Reference: REST API reference for every Hanzo service, generated from OpenAPI specs. - [API Reference](/docs/openapi): The unified REST API reference for every Hanzo product — 38 services, one key, generated from OpenAPI 3.1 specs. - [Hanzo AI — Inference API](/docs/openapi/ai): Top-level OpenAI- and Claude-compatible inference surface (hanzoai/ai). - [Hanzo Analytics API](/docs/openapi/analytics): Web analytics API for tracking website traffic, events, sessions, and generating reports. - [Hanzo App — Projects & Deployments](/docs/openapi/app): Site/app projects, builds and deployments for hanzo.app. - [Hanzo Auto API](/docs/openapi/auto): Hanzo Auto is a workflow automation platform for building trigger-based - [Hanzo Base — Collections](/docs/openapi/base): Schema-driven records store (Hanzo Base) over IAM-native collections. - [Hanzo Bot API](/docs/openapi/bot): Hanzo Bot Hub is the skill registry and marketplace for Hanzo Bot. - [Hanzo Chat API](/docs/openapi/chat): REST API for Hanzo Chat, an AI chat interface with multi-model support, - [Hanzo Cloud API](/docs/openapi/cloud): Hanzo Cloud Backend API — AI model management, inference, and usage tracking. - [Hanzo Commerce API](/docs/openapi/commerce): Hanzo Commerce API provides a complete e-commerce platform with support for - [Hanzo Console API](/docs/openapi/console): Hanzo Console is an LLM engineering platform for observability, prompt management, - [Hanzo DB API](/docs/openapi/db): Hanzo DB provides serverless PostgreSQL with instant branching, autoscaling - [Hanzo DID API](/docs/openapi/did): Hanzo DID provides decentralized identity, user profiles, organization - [Hanzo DNS API](/docs/openapi/dns): Hanzo DNS provides authoritative DNS hosting with a REST API for - [Hanzo Edge API](/docs/openapi/edge): Hanzo Edge provides serverless edge functions with global deployment, - [Hanzo Engine API](/docs/openapi/engine): Hanzo Engine provides GPU cluster management, ML job orchestration, - [Hanzo Evals API](/docs/openapi/evals): LLM evaluation for Hanzo Cloud — the `/v1/evals/*` surface served by the - [Hanzo Flow API](/docs/openapi/flow): Hanzo Flow is a visual workflow automation platform for building AI-powered - [Hanzo Gateway API](/docs/openapi/gateway): Hanzo Gateway provides a unified LLM API gateway with support for multiple providers, - [Hanzo Guard API](/docs/openapi/guard): Hanzo Guard provides LLM I/O sanitization via an HTTP proxy API. - [Hanzo IAM API](/docs/openapi/iam): Hanzo IAM — Identity and Access Management (OAuth2, OIDC, SAML, Web3) - [Hanzo KMS API](/docs/openapi/kms): Hanzo KMS is a key management service for managing secrets, API keys, - [Hanzo KV API](/docs/openapi/kv): Hanzo KV provides a managed key-value store with caching, pub/sub messaging, - [Hanzo ML API](/docs/openapi/ml): Hanzo ML provides end-to-end MLOps pipeline management including - [Hanzo MQ API](/docs/openapi/mq): Hanzo MQ provides a managed message queue and pub/sub service built on - [Hanzo Nexus API](/docs/openapi/nexus): Hanzo Nexus is a knowledge base and RAG (Retrieval-Augmented Generation) platform. It provides document management, vector embeddings, semantic search, and AI-powered question answering across organiz - [Hanzo O11y API](/docs/openapi/o11y): Hanzo O11y provides unified observability with logs, metrics, and traces - [Hanzo Operative API](/docs/openapi/operative): Hanzo Operative is a computer-use agent that allows Claude to interact with - [Hanzo PaaS API](/docs/openapi/paas): Production PaaS for Hanzo Platform — K8s-native GitOps deployments, - [Hanzo Platform API](/docs/openapi/platform): PaaS API for Hanzo Platform (platform.hanzo.ai) — deployments, - [Hanzo Pricing API](/docs/openapi/pricing): Unified pricing API for the Hanzo AI platform. Serves real-time pricing - [Hanzo PubSub API](/docs/openapi/pubsub): Hanzo PubSub provides high-performance publish/subscribe messaging with - [Hanzo Registry API](/docs/openapi/registry): Hanzo Registry provides a container image registry with vulnerability scanning, - [Hanzo S3 API](/docs/openapi/s3): Hanzo S3 provides S3-compatible object storage for AI infrastructure. - [Hanzo Search API](/docs/openapi/search): Hanzo Search is a high-performance, typo-tolerant search engine - [Hanzo Stream API](/docs/openapi/stream): Hanzo Stream is a Kafka-compatible streaming gateway built on Hanzo PubSub. - [Hanzo Vector API](/docs/openapi/vector): Hanzo Vector provides a high-performance vector database for embeddings, - [Hanzo Visor API](/docs/openapi/visor): Hanzo Visor is a VM and remote session management platform. - [Hanzo ZT API](/docs/openapi/zt): Hanzo ZT provides programmable zero-trust networking for AI infrastructure. - SDKs: Official Hanzo SDKs for Python, TypeScript, Go, Rust, and C - [SDKs](/docs/sdks): Official Hanzo SDKs for Python, TypeScript, Go, Rust, and C/C++. - [Python SDK](/docs/sdks/python): The official Hanzo Python SDK — OpenAI-compatible client for the LLM Gateway. - [TypeScript SDK](/docs/sdks/typescript): The official Hanzo TypeScript/JavaScript SDK for Node.js, Deno, and browsers. - [Go SDK](/docs/sdks/go): The official Hanzo Go SDK for building AI-powered Go applications. - [Rust SDK](/docs/sdks/rust): The official Hanzo Rust SDK with async support and crypto/DID features. - [C/C++ SDK](/docs/sdks/c): The official Hanzo C/C++ SDK for high-performance native applications. - [IAM SDK](/docs/sdks/iam): TypeScript SDK for Hanzo IAM — authentication, organizations, billing, and React bindings. - **Data Collection** - [AST (AI Structured Training)](/docs/sdks/ast): Structured AI training data collection SDK for capturing interactions, feedback, and model outputs. - [Gateway](/docs/gateway): The unified, gated, priced API gateway for Hanzo Cloud at api.hanzo.ai -- one entry point, one key, every service. - [Console](/docs/console): The unified cloud console for Hanzo Cloud -- manage every product, key, and organization from one app at console.hanzo.ai. - [Integrations](/docs/integrations): Connect blob storage, Slack, Mixpanel, and Insights to your project. - Integrations & Extensions: Install and connect Hanzo everywhere you work — one API key, one identity. - [Integrations & Extensions](/docs/apps): Install and connect Hanzo across your browser, editor, desktop, docs, design tools, and business apps — one API key, one identity, everywhere. - [Browser](/docs/apps/browser): Hanzo in Chrome, Edge, Firefox, and Safari — AI chat, page context, and one-click actions on any tab. - [IDEs & Editors](/docs/apps/ides): Hanzo in VS Code, Cursor, Windsurf, Antigravity, JetBrains, and JupyterLab — an inline AI coding assistant and agent. - [Desktop](/docs/apps/desktop): The Hanzo desktop app for macOS, Windows, and Linux — a menubar assistant with a global hotkey — plus the Claude Desktop connector. - [Docs & Office](/docs/apps/office): Hanzo in Word, Excel, PowerPoint, Outlook, Google Workspace, and PDF — draft, summarize, and edit documents in place. - [Design](/docs/apps/design): Hanzo in Figma and Sketch — generate, rename, and annotate layers and copy from your AI assistant. - [Comms](/docs/apps/comms): Hanzo in Slack, Zoom, Google Meet, Microsoft Teams, and Zendesk — summarize threads and meetings and draft replies in the tools your team already uses. - [Business](/docs/apps/business): Connect Hanzo to Salesforce, DocuSign, Notion, HubSpot, and Shopify — summarize records, draft content, and act on your business data over OAuth. - [Dev](/docs/apps/dev): The Hanzo GitHub App and GitLab integration — automated PR/MR review, issue triage, and @hanzo mentions in your repos. - [Productivity](/docs/apps/productivity): Hanzo in Clio and Raycast — AI in your legal practice management and one keystroke away from your command bar. - [Verticals](/docs/apps/verticals): Industry integrations — Epic (healthcare), Procore (construction), and QuickBooks (finance) — connected over their native app models with data kept server-side. - **Products** - Hanzo Studio - [Hanzo Studio](/docs/studio): Visual AI engine for building image, video, 3D, and audio workflows. Node-based editor with GPU scaling, multi-tenant isolation, and enterprise billing. - [AI Studio](/docs/ai-studio): Hanzo AI Studio — build, test, and ship AI apps and pipelines visually. - Hanzo Chat: Hanzo Chat — AI chat platform - [Hanzo Chat](/docs/chat): AI chat platform with Zen models, 100+ third-party models, MCP tools, agents, file uploads, and RAG. Self-host or use hosted at chat.hanzo.ai. - [Features](/docs/chat/features): Hanzo Chat features — presets, file uploads, RAG, search, vision, conversation import/export, bookmarks, and more. - [Configuration](/docs/chat/configuration): Configure Hanzo Chat — models, endpoints, MCP tools, environment variables, and chat.yaml reference. - [Models](/docs/chat/models): All models available in Hanzo Chat — 14 Zen models and 100+ third-party from OpenAI, Anthropic, Google, Meta, Mistral, Together, and Groq. - [Agents](/docs/chat/agents): Create custom AI agents in Hanzo Chat with system prompts, model selection, and MCP tool access. - [File Uploads & RAG](/docs/chat/file-uploads): Upload files to Hanzo Chat for context-aware responses using Retrieval-Augmented Generation (RAG). - [Plugins](/docs/chat/plugins): Hanzo Chat plugin system — built-in plugins, ChatGPT plugins, and custom plugin development. - [Moderation](/docs/chat/moderation): Automated moderation system for Hanzo Chat — rate limiting, violation tracking, and user bans. - [Self-Hosting](/docs/chat/self-hosting): Deploy Hanzo Chat with Docker, Kubernetes, or on cloud providers. Full self-hosting guide with production configuration. - [Authentication](/docs/chat/authentication): Configure authentication for Hanzo Chat — Hanzo IAM, OAuth2/OIDC, social login, and local auth. - [Environment Variables](/docs/chat/environment): Complete reference for all Hanzo Chat environment variables — server, database, auth, models, moderation, and more. - [LLM Gateway](/docs/llm): Unified proxy for 200+ LLM providers. One API, all models. Load balancing, caching, rate limiting, and observability. - [MCP](/docs/mcp): Model Context Protocol as a Service — Launch any MCP server with one command. 260+ tools available. - Hanzo Dev: AI-powered coding assistant for your terminal - [Hanzo Dev](/docs/dev): AI-powered coding assistant for your terminal. Install, configure, and operate Hanzo Dev. - Getting Started: Install and set up Hanzo Dev - [Getting Started](/docs/dev/getting-started): Get up and running with Hanzo Dev in minutes. - [Installation](/docs/dev/getting-started/install): Install Hanzo Dev from npm, Homebrew, or build from source. - [Homebrew](/docs/dev/getting-started/homebrew): Install Hanzo Dev via Homebrew on macOS. - [Authentication](/docs/dev/getting-started/authentication): Set up authentication for Hanzo Dev. - Usage: How to use Hanzo Dev - **Commands** - [Usage](/docs/dev/usage): Learn how to use Hanzo Dev for interactive and non-interactive AI-powered development. - [Non-Interactive Mode](/docs/dev/usage/exec): Run Hanzo Dev headless for single tasks and CI/CD pipelines. - [Execution Policy](/docs/dev/usage/execpolicy): Control how Hanzo Dev executes commands with execution policy rules. - [Slash Commands](/docs/dev/usage/slash-commands): All built-in slash commands available in the Hanzo Dev TUI. - **Features** - [Auto Drive](/docs/dev/usage/auto-drive): Fully automated multi-turn task execution in Hanzo Dev. - [Agents & Subagents](/docs/dev/usage/agents): Configure and orchestrate external CLI agents and multi-agent workflows. - [Settings](/docs/dev/usage/settings): Full-screen TUI settings panel for model, theme, agents, and more. - [Custom Prompts](/docs/dev/usage/prompts): Create and manage custom prompt snippets in Hanzo Dev. - [Skills](/docs/dev/usage/skills): Extend Hanzo Dev with reusable skill bundles. - [JavaScript REPL](/docs/dev/usage/js-repl): Run JavaScript in a persistent Node-backed kernel with top-level await. - **Advanced** - [Advanced Usage](/docs/dev/usage/advanced): CI/CD integration, MCP configuration, verbose logging, and advanced workflows. - Configuration: Configure and secure Hanzo Dev - [Configuration](/docs/dev/configuration): Configure Hanzo Dev with config.toml, environment variables, and CLI flags. - [Example Configuration](/docs/dev/configuration/example-config): Annotated sample config.toml for Hanzo Dev. - [Sandboxing](/docs/dev/configuration/sandbox): How Hanzo Dev sandboxes command execution for safety. - [Platform Sandboxing](/docs/dev/configuration/platform-sandboxing): OS-specific sandboxing mechanisms in Hanzo Dev. - Integrations: IDE and tool integrations for Hanzo Dev - [Integrations](/docs/dev/integrations): Connect Hanzo Dev with your favorite editors and tools. - [Zed Integration](/docs/dev/integrations/zed): Use Hanzo Dev as an external agent in the Zed editor via ACP. - [GitHub Copilot](/docs/dev/integrations/copilot): GitHub Copilot CLI integration for AI-powered code assistance. - [Agent Platform (Local + Cloud)](/docs/dev/integrations/agent-platform): Unify Hanzo Dev local sessions with Agent Base and Agent Field cloud tracking. - Architecture - [Architecture](/docs/dev/architecture): System design and component overview for Hanzo Dev. - [Agent Mesh Architecture](/docs/dev/architecture/agent-mesh): ZAP + RNS + Consensus + x402 — high performance mesh collective intelligence for multi-agent coordination. - Reference: CLI reference and API documentation - [Reference](/docs/dev/reference): Complete command-line reference for Hanzo Dev. - [CLI Reference](/docs/dev/reference/cli): Complete command-line reference for the dev CLI tool. - Contributing: How to contribute to Hanzo Dev - [Contributing](/docs/dev/contributing): Guidelines for contributing to Hanzo Dev. - [Contributor License Agreement](/docs/dev/contributing/cla): CLA requirements for contributing to Hanzo Dev. - [FAQ](/docs/dev/faq): Frequently asked questions about Hanzo Dev. - Hanzo ZAP: Zero-Copy App Proto for AI agent communication - [ZAP Protocol](/docs/zap): Zero-Copy App Proto — High-performance Cap'n Proto RPC for AI agent communication. 10-100x faster than MCP with post-quantum security. - Overview: ZAP architecture and concepts - [Overview](/docs/zap/overview): Understanding ZAP architecture and core concepts - [ZAP vs MCP](/docs/zap/overview/comparison): Detailed comparison between ZAP and Model Context Protocol - [Architecture](/docs/zap/overview/architecture): ZAP system architecture and component design - [Getting Started](/docs/zap/getting-started): Install ZAP and build your first AI agent - [Schema Language](/docs/zap/schema): Cap'n Proto schema reference for ZAP - [Protocol Specification](/docs/zap/protocol): ZAP wire format, encoding, and RPC semantics - Language Bindings: SDK documentation for all languages - [Language Bindings](/docs/zap/bindings): ZAP SDK documentation for all supported languages - [Rust](/docs/zap/bindings/rust): ZAP Rust SDK - Reference implementation - [Go](/docs/zap/bindings/go): ZAP Go SDK - Idiomatic Go binding - [Python](/docs/zap/bindings/python): ZAP Python SDK - Async/await API - [JavaScript](/docs/zap/bindings/javascript): ZAP JavaScript SDK - Node.js and browser support - [C++](/docs/zap/bindings/cpp): ZAP C++ SDK - High-performance native binding - [C](/docs/zap/bindings/c): ZAP C SDK - Minimal C API for embedded systems - [Java](/docs/zap/bindings/java): ZAP Java SDK - JVM binding with Netty transport - [C#](/docs/zap/bindings/csharp): ZAP C# SDK - .NET binding with async support - [Erlang](/docs/zap/bindings/erlang): ZAP Erlang SDK - OTP-compatible binding - [OCaml](/docs/zap/bindings/ocaml): ZAP OCaml SDK - Functional binding with Lwt - [Haskell](/docs/zap/bindings/haskell): ZAP Haskell SDK - Pure functional binding - Advanced Topics: Post-quantum crypto, consensus, identity - [Advanced Topics](/docs/zap/advanced): Post-quantum cryptography, consensus, identity, and blockchain integration - [Post-Quantum Cryptography](/docs/zap/advanced/post-quantum): ML-KEM, ML-DSA, and hybrid key exchange in ZAP - [Corona Consensus](/docs/zap/advanced/corona): Threshold lattice-based signing for distributed agents - [Agent Consensus](/docs/zap/advanced/agent-consensus): Voting-based response aggregation for multi-agent systems - [W3C DID Support](/docs/zap/advanced/did): Decentralized identity integration in ZAP - [Lux Integration](/docs/zap/advanced/lux): Blockchain anchoring and staking on Lux Network - [Agents](/docs/agents): Build, deploy, and run autonomous agents — personas with a model, tools, guardrails, and shared memory. - [Prompts](/docs/prompts): Versioned prompts with labels and history — manage, ship, and roll back prompts through one API. - [Hanzo Embeddings](/docs/embeddings): Generate, store, and search vector embeddings at scale — an OpenAI-compatible embeddings API on the Hanzo gateway that pairs with Vector. - [Marketplace](/docs/marketplace): Browse and deploy AI models and providers — real pricing and live availability. - **Cloud: Data** - [Hanzo SQL](/docs/sql): Managed PostgreSQL — provision databases, create copy-on-write branches, and scale reads with replicas over a single API and the standard Postgres wire protocol. - [Hanzo Vector](/docs/vector): Managed vector database for embeddings and semantic search — HNSW indexing, metadata filtering, and hybrid search, provisioned in one API call. - [Hanzo KV](/docs/kv): Managed key-value store — a Redis/Valkey-compatible cache, queue, and pub/sub engine with sub-millisecond reads, provisioned in one API call. - [Hanzo Search](/docs/search): Managed search — full-text and hybrid indexes with typo tolerance, faceted filtering, and sub-50ms queries, provisioned in one API call. - [Hanzo Datastore](/docs/datastore): Managed column-oriented analytics store — run sub-second SQL over billions of rows with a ClickHouse-compatible OLAP engine. - [Hanzo DocDB](/docs/docdb): Managed document database — a MongoDB-compatible store with BSON documents, aggregation pipelines, and secondary indexes, backed by PostgreSQL. - [Hanzo Storage](/docs/storage): S3-compatible object storage — durable, versioned buckets for models, datasets, and media that work with any S3 client or SDK. - [Hanzo Base](/docs/base): Multi-tenant Hanzo Base — provision and manage tenant backend instances, each a single-binary BaaS with REST, auth, realtime, and file storage. - [Hanzo Memory](/docs/memory): Your personal memory — a searchable, editable long-term memory service for agents and apps, built on semantic vector search. - **Cloud: Compute & Deploy** - [GPUs](/docs/gpus): On-demand H100/H200/A100/L40S GPU compute — metered by the hour, provisioned from the console or API, billed to your org's cloud-usage ledger. - [Machines](/docs/machines): Compute machines and capacity across regions — the nodes of your clusters. - [Edge](/docs/edge): Compute at the edge — on-device AI inference close to your users, offline and private. - [Hanzo Functions](/docs/functions): Serverless compute platform - [Pipelines](/docs/pipelines): CI/CD pipelines from commit to deploy — build, push, and reconcile your fleet. - [Hanzo Registry](/docs/registry): Container images and artifacts — a self-hosted, S3-backed OCI registry at registry.hanzo.ai, mirrored to ghcr.io/hanzoai. - [Networks](/docs/networks): Blockchain networks — chain, nodes, status, and RPC endpoints. - [Blockchain](/docs/blockchain): On-chain settlement and networks — chain, RPC, and block explorer. - **Observability** - [Hanzo O11y](/docs/o11y): Full-stack observability platform - [Metrics](/docs/metrics): Product metrics, events, and sessions — OpenTelemetry- and Prometheus-compatible time series for your workloads. - [Logs](/docs/logs): Structured logs across all services — OpenTelemetry-compatible, correlated to traces by trace id. - [Traces](/docs/traces): Distributed traces across all services — OpenTelemetry-compatible, correlated with logs, metrics, and scores. - [Sessions](/docs/sessions): Traces grouped into multi-turn sessions — one conversation or agent run across many requests. - [Dashboards](/docs/dashboards): Product analytics and observability dashboards for Hanzo Cloud -- usage, cost, latency, and health in one view. - **Evaluation** - [Datasets](/docs/datasets): Curate evaluation datasets and items — the input/expected-output pairs your experiments run against. - [Experiments](/docs/experiments): Dataset runs, comparisons, and experiment analytics — score a dataset against a model and compare runs. - [Scores](/docs/scores): Evaluation scores from feedback, graders, and review — attached to traces, observations, and sessions. - [Score Configs](/docs/score-configs): Score definitions — data types, ranges, and categories that every score conforms to. - [Annotation Queues](/docs/annotation-queues): Review queues for scoring traces and observations against a defined set of score configs. - **Security & Identity** - [IAM](/docs/iam): Organizations, users, and roles (RBAC) for Hanzo Cloud, powered by Hanzo IAM and the hanzo.id OIDC issuer. - [KMS](/docs/kms): Encryption keys, secrets, and cryptographic operations for Hanzo Cloud -- the secrets control plane, Hanzo KMS. - [Authz](/docs/authz): Fine-grained authorization policies and access checks for Hanzo Cloud -- model-based access control powered by Hanzo Authz. - [MPC](/docs/mpc): Threshold signing and multi-party computation for Hanzo Cloud -- split-key custody with post-quantum finality, powered by Hanzo MPC. - [Zero Trust](/docs/zero-trust): Private service access for Hanzo Cloud -- routers, identities, policies, and sessions over an identity-based mTLS overlay. - [Hanzo Zero Trust](/docs/zt): Programmable zero-trust networking - **Commerce & Billing** - Commerce: Hanzo Commerce — billing, payments, subscriptions - [Overview](/docs/commerce): Hanzo Commerce - Full-stack e-commerce platform with AI-powered recommendations - [Quick Start](/docs/commerce/quickstart): Get up and running with Hanzo Commerce in minutes - [Architecture](/docs/commerce/architecture): Modular architecture overview for Hanzo Commerce - Commerce Modules: Core commerce modules - [Commerce Modules](/docs/commerce/modules): Core modules that power Hanzo Commerce - [Product Module](/docs/commerce/modules/product): Products, variants, options, images, and collections - [Order Module](/docs/commerce/modules/order): Order lifecycle, status management, returns, and exchanges - [Cart Module](/docs/commerce/modules/cart): Shopping cart operations, line items, promotions, and tax calculation - [Payment Module](/docs/commerce/modules/payment): Payment providers, authorization, capture, refunds, and webhooks - [Customer Module](/docs/commerce/modules/customer): Customer accounts, authentication, addresses, and groups - [Fulfillment Module](/docs/commerce/modules/fulfillment): Shipping profiles, zones, providers, and tracking - [Inventory Module](/docs/commerce/modules/inventory): Stock levels, reservations, locations, and multi-warehouse support - [Pricing Module](/docs/commerce/modules/pricing): Price lists, volume tiers, rules, sale pricing, and multi-currency - [Promotion Module](/docs/commerce/modules/promotion): Coupons, discounts, campaigns, and automatic promotions - [Tax Module](/docs/commerce/modules/tax): Tax regions, rates, rules, providers, and automated calculation - [Region Module](/docs/commerce/modules/region): Multi-region support, currencies, countries, and localization - [Analytics Module](/docs/commerce/modules/analytics): Commerce events, dashboards, and ClickHouse integration - [Subscription Module](/docs/commerce/modules/subscription): Recurring billing, plans, trials, and usage-based pricing - Storefront Development - [Storefront Development](/docs/commerce/storefront): Build customer-facing storefronts with the Hanzo Commerce SDK - [Products](/docs/commerce/storefront/products): Display products, collections, and search results in your storefront - [Cart](/docs/commerce/storefront/cart): Create and manage shopping carts in your storefront - [Checkout](/docs/commerce/storefront/checkout): Implement the complete checkout flow in your storefront - [Customers](/docs/commerce/storefront/customers): Registration, login, profile management, and order history - [Regions](/docs/commerce/storefront/regions): Multi-region and multi-currency handling in your storefront - Admin Dashboard - [Admin Dashboard](/docs/commerce/admin): Overview of the Hanzo Commerce Admin Dashboard for managing your store - [Setup & Configuration](/docs/commerce/admin/setup): Install, configure, and deploy the Hanzo Commerce Admin Dashboard - [Product Management](/docs/commerce/admin/products): Create and manage products, variants, collections, and inventory in the admin dashboard - [Order Management](/docs/commerce/admin/orders): View, process, and manage orders through their complete lifecycle - [Customer Management](/docs/commerce/admin/customers): View and manage customer profiles, groups, and order history - [Store Settings](/docs/commerce/admin/settings): Configure regions, currencies, taxes, shipping, payments, and team access - SDK Reference - [SDK Overview](/docs/commerce/sdk): Install and use @hanzo/sdk to interact with the Hanzo Commerce API - [Auth Module](/docs/commerce/sdk/auth): Authentication with @hanzo/sdk -- login, register, tokens, and OAuth - [Admin Module](/docs/commerce/sdk/admin): Complete reference for the @hanzo/sdk admin module -- manage products, orders, customers, and more - [Store Module](/docs/commerce/sdk/store): Storefront SDK reference -- browse products, manage carts, and complete checkout - [Error Handling](/docs/commerce/sdk/errors): Handle errors from @hanzo/sdk -- error codes, retry strategies, and validation - [TypeScript Types](/docs/commerce/sdk/types): Type reference for @hanzo/sdk -- key interfaces and how to use them - Guides: Setup and integration guides for Hanzo Commerce - [Guides](/docs/commerce/guides): Setup and integration guides for Hanzo Commerce - [Authentication](/docs/commerce/guides/authentication): Implement user authentication with Hanzo ID OAuth2 - [Products](/docs/commerce/guides/products): Manage your product catalog with variants and collections - [Shopping Cart](/docs/commerce/guides/cart): Implement persistent shopping carts with discounts and coupons - [Orders](/docs/commerce/guides/orders): Complete order lifecycle management with fulfillment and returns - [Payments](/docs/commerce/guides/payments): Process payments with multiple providers including crypto - [Analytics](/docs/commerce/guides/analytics): ClickHouse-powered analytics with real-time dashboards - [Fulfillment](/docs/commerce/guides/fulfillment): Set up shipping profiles, service zones, and process order fulfillments - [Inventory Management](/docs/commerce/guides/inventory): Set up stock locations, manage inventory levels, and handle reservations - [Promotions & Discounts](/docs/commerce/guides/promotions): Create promotions, configure discount rules, and manage campaigns - [Multi-Region Commerce](/docs/commerce/guides/multi-region): Configure regions, currencies, taxes, and localized pricing - API Reference: Complete Hanzo Commerce API documentation - [API Reference](/docs/commerce/api): Complete Hanzo Commerce REST API documentation - [Authentication API](/docs/commerce/api/authentication): OAuth2 tokens, API keys, and session management - [Product API](/docs/commerce/api/products): Manage product catalog, media, and metadata - [Variant API](/docs/commerce/api/variants): Manage product variants, options, pricing, and inventory links - [Collections API](/docs/commerce/api/collections): Organize products into collections with manual or automated rules - [Cart API](/docs/commerce/api/cart): Manage shopping carts, line items, promotions, and checkout preparation - [Order API](/docs/commerce/api/orders): Manage orders, fulfillment, cancellations, and refunds - [Payment API](/docs/commerce/api/payments): Process payments, authorizations, captures, and refunds - [User API](/docs/commerce/api/users): Manage admin users, roles, and permissions - [Webhooks API](/docs/commerce/api/webhooks): Configure event notifications, verify signatures, and manage delivery - [Customer API](/docs/commerce/api/customers): Manage customer accounts, profiles, and segmentation - [Fulfillment API](/docs/commerce/api/fulfillment): Manage shipping profiles, service zones, and order fulfillment - [Inventory API](/docs/commerce/api/inventory): Track stock levels, reservations, and multi-warehouse inventory - [Coupons & Promotions API](/docs/commerce/api/coupons): Manage promotions, discount rules, and campaign budgets - [Subscription API](/docs/commerce/api/subscriptions): Manage recurring subscriptions, plans, and billing cycles - [Tax API](/docs/commerce/api/tax): Configure tax regions, rates, and automatic tax calculation - [Region API](/docs/commerce/api/regions): Manage sales regions, currencies, and country assignments - [Notification API](/docs/commerce/api/notifications): Manage transactional notifications across email, SMS, and push channels - [Analytics API](/docs/commerce/api/analytics): Track events, query metrics, and retrieve dashboard data - [Upload API](/docs/commerce/api/uploads): Upload files, generate presigned URLs, and manage media assets - Recipes - [Recipes](/docs/commerce/recipes): End-to-end guides for common Hanzo Commerce use cases - [Next.js Storefront](/docs/commerce/recipes/nextjs-storefront): Build a production-ready storefront with Next.js 14 and @hanzo/commerce - [Digital Products](/docs/commerce/recipes/digital-products): Sell software, ebooks, and courses with instant digital fulfillment - [Subscriptions](/docs/commerce/recipes/subscriptions): Set up recurring billing with plan management and lifecycle handling - [Multi-Currency](/docs/commerce/recipes/multi-currency): Serve international customers with region-specific currencies and pricing - [Marketplace](/docs/commerce/recipes/marketplace): Build a multi-vendor marketplace with split payments and vendor management - [B2B Commerce](/docs/commerce/recipes/b2b): Enterprise commerce with customer groups, bulk ordering, and purchase orders - Deployment - [Deployment](/docs/commerce/deployment): Deploy Hanzo Commerce to production with best practices - [Docker](/docs/commerce/deployment/docker): Deploy Hanzo Commerce with Docker and compose.yml - [Kubernetes](/docs/commerce/deployment/kubernetes): Deploy Hanzo Commerce on Kubernetes with Helm charts and autoscaling - [Vercel](/docs/commerce/deployment/vercel): Deploy the Next.js storefront and docs to Vercel - [Self-Hosted](/docs/commerce/deployment/self-hosted): Deploy Hanzo Commerce on bare metal or a VPS with systemd and Nginx - [Billing](/docs/billing): Usage, credits, invoices, and payment methods for Hanzo Cloud -- usage-based metering, cloud credits, and on-chain HUSD top-up. - [Referrals](/docs/referrals): Your referral link, invite history, and cloud-credit earnings on Hanzo Cloud -- refer developers, earn credits and revenue share. - **Proof of AI** - Proof of AI: Verifiable inference, node operators, and open-source payouts - [Proof of AI](/docs/proof-of-ai): How Hanzo verifies AI computation on-chain, how node operators get paid, and how the cloud pays the open-source developers it runs on. - [Node Operator Guide](/docs/proof-of-ai/node-operator): Run Hanzo Node, advertise capabilities, receive work, and get paid — plus the trust and TEE attestation requirements, with an honest line between what works today and what is roadmap. - [Open-Source Payouts](/docs/proof-of-ai/oss-payouts): How Hanzo Cloud attributes usage to the open-source packages it runs and pays their authors — the 25% commitment, the attribution pipeline, and how to participate, with an honest line between live and roadmap. - **Infrastructure** - [Hanzo Tasks](/docs/tasks): Durable workflow execution engine - [Hanzo PubSub](/docs/pubsub): High-performance messaging and streaming - [Crawl](/docs/crawl): Crawl and extract the web for your agents — a Firecrawl-compatible API. - **Skills Reference** - Hanzo Skills Reference: Comprehensive reference for all 126 Hanzo skills - [Hanzo Skills Reference](/docs/skills): Comprehensive reference documentation for all 49 Hanzo skills — deep-dive guides for AI agents and developers. - **AI & Agents** - [How to Use AI with Hanzo and Lux](/docs/skills/ai-development-guide): This guide covers setting up Hanzo's full AI development stack — extensions, CLI agents, MCP tools, Zen models, and skills for cross-stack work across Hanzo AI and Lux blockchain. - [Hanzo ACI](/docs/skills/hanzo-aci): Hanzo ACI (Agent Computer Interface) is a Python toolkit that gives AI agents the ability to edit files, lint code, index codebases, execute shell commands, and convert documents. It provides the b... - [Hanzo Agent SDK - Multi-Agent Orchestration Framework](/docs/skills/hanzo-agent): Hanzo Agent SDK is a Python multi-agent framework — fork of OpenAI's Agents SDK with Hanzo AI integration. Build autonomous agents that plan, use tools, coordinate with other agents, and maintain m... - [Hanzo Bot - Multi-Channel AI Messaging Gateway](/docs/skills/hanzo-bot): Hanzo Bot (`@hanzo/bot`) is a TypeScript ESM multi-channel AI messaging gateway that connects AI agents to messaging platforms through a plugin/extension architecture. It provides first-class integ... - [Hanzo Code](/docs/skills/hanzo-code): Hanzo Code is an open-source AI-native code editor -- a fork of VS Code (microsoft/vscode) with integrated LLM chat, autocomplete, inline diffs, and agent tool use baked directly into the editor co... - [Hanzo Computer](/docs/skills/hanzo-computer): Hanzo Computer (`hanzoai/computer`) is an ecommerce web application for purchasing AI compute hardware. It sells the DGX Spark instance ($4,000) as the only credit-card purchasable product, with GP... - [Hanzo Dev - AI-Powered Development Platform](/docs/skills/hanzo-dev): Hanzo Dev is an AI-powered development platform -- a monorepo containing a Rust-native CLI (`dev`, `dev-tui`, `dev-exec`), a Node.js wrapper CLI (`@hanzo/dev`), a legacy TypeScript CLI (`codex-cli`... - [Hanzo MCP - Agentic Development with Model Context Protocol](/docs/skills/hanzo-mcp): Hanzo MCP is the agentic workflow layer of the Hanzo ecosystem. It implements the Model Context Protocol — a standard for exposing tools, resources, and prompts to AI agents. Ships 13 HIP-0300 unif... - [Hanzo Memory](/docs/skills/hanzo-memory): Hanzo Memory (`@hanzo/memory`) is a TypeScript AI memory service that stores, searches, and retrieves contextual memories using vector embeddings. It provides a REST API server (Fastify) and a Type... - [Hanzo Operative - Computer Use Agent](/docs/skills/hanzo-operative): Hanzo Operative (`hanzo-operative`) is an autonomous computer use agent that enables AI to control desktop environments via screenshots, mouse, keyboard, and bash commands. It uses Anthropic's Clau... - [Hanzo Tools](/docs/skills/hanzo-tools): Hanzo Tools is a unified registry of 88 tools across 20 categories for all AI agent operations across the Hanzo and Zoo ecosystems. Core implementation in Rust with Python (PyO3) and Node.js (NAPI-... - [Hanzo vLLM](/docs/skills/hanzo-vllm): Hanzo vLLM is a Rust LLM inference server with an OpenAI-compatible API, PagedAttention, continuous batching, and multi-GPU/multi-node support. Fork of `EricLBuehler/candle-vllm`, built on top of `... - **Apps & Design** - [Hanzo App](/docs/skills/hanzo-app): Hanzo App is an AI-powered developer platform that serves as both a web-based development environment (hanzo.app) and a macOS desktop assistant. Built with Next.js 15 and React 19 for the web front... - [Hanzo Brand Guidelines](/docs/skills/hanzo-brand): Brand assets, color palette, typography, and guidelines for the Hanzo ecosystem. - [Hanzo Desktop - Cross-Platform AI Agent Builder](/docs/skills/hanzo-desktop): Hanzo Desktop is a cross-platform desktop application for creating and managing AI agents without code. Built with Tauri (Rust backend + React frontend) and managed as an NX monorepo, it provides a... - [Hanzo Docs - Multi-Brand Documentation Platform](/docs/skills/hanzo-docs): Hanzo Docs is a multi-brand documentation platform — fork of Hanzo Docs with 27 packages and 15 apps. Serves documentation for Hanzo, Lux, Zoo, and Zen brands from a single monorepo with shared compo... - [Hanzo Editor](/docs/skills/hanzo-editor): Hanzo Editor (`hanzoai/code`) is an open-source AI-native code editor -- a VS Code fork (originally "Void Editor") with LLM chat, autocomplete, inline diffs, and agent tool use built directly into ... - [Hanzo Extensions - Browser & IDE Plugins](/docs/skills/hanzo-extension): Hanzo Extensions is a monorepo of browser and IDE extensions providing AI-powered development and browsing tools. - [Hanzo Flow](/docs/skills/hanzo-flow): Visual AI Workflow Builder - [Hanzo Live - Real-Time AI Streaming](/docs/skills/hanzo-live): Hanzo Live provides real-time AI streaming infrastructure for building responsive, collaborative AI applications. - [Hanzo Playground](/docs/skills/hanzo-playground): Control Plane for AI Bots - [Hanzo Search - High-Performance Search Engine](/docs/skills/hanzo-search): Hanzo Search is a high-performance search engine built as a Rust workspace with 22 crates. Fork of Meilisearch v1.37.0 with AI-powered ranking, vector search, and faceting. Designed for sub-50ms se... - [Hanzo Store](/docs/skills/hanzo-store): Hanzo Store is a flatfile-based marketplace for discovering and installing AI agent tools and MCP servers. Built with Next.js 15 and static site generation, it serves as the app store for Hanzo Des... - [Hanzo Studio - Visual AI Workflow Engine](/docs/skills/hanzo-studio): Hanzo Studio is a visual node-based AI workflow engine for building, testing, and deploying AI pipelines. - [Hanzo Suite](/docs/skills/hanzo-suite): Hanzo Business Suite is a fork of Odoo 18.0 (Community Edition) providing a full-featured open-source ERP/CRM platform tightly integrated with Hanzo AI infrastructure. It includes CRM, e-commerce, ... - [Hanzo UI - Component Library (shadcn/ui Fork)](/docs/skills/hanzo-ui): Hanzo UI is a React component library forked from shadcn/ui, extended with 161+ components (3x more than upstream), two themes, multi-framework support, AI components, 3D components, and a visual p... - [Hanzo Website](/docs/skills/hanzo-website): The Hanzo AI corporate website at hanzo.ai. A Next.js 16 App Router site with static export (`output: 'export'`), React 19, Tailwind CSS 4, Framer Motion animations, and shadcn/ui components. Dark ... - **Blockchain & Web3** - [Hanzo Contracts - AI Infrastructure Smart Contracts](/docs/skills/hanzo-contracts): Hanzo Contracts is the smart contract repository for the Hanzo AI ecosystem. Built with Foundry and Solidity 0.8.31, it contains three core contracts for the AI token economy, faucet distribution, ... - [Hanzo EVM - Rust Execution Engine for Post-Quantum Web3](/docs/skills/hanzo-evm): Hanzo EVM is a Rust-based EVM execution engine — fork of paradigmxyz/reth v1.11.0, rebranded for the Hanzo ecosystem. - [Hanzo Explorer](/docs/skills/hanzo-explorer): Hanzo Explorer is an EVM blockchain explorer for inspecting and analyzing transactions, accounts, smart contracts, and tokens on Lux Network and other EVM-compatible chains. It is a fork of Blocksc... - [Hanzo Faucet](/docs/skills/hanzo-faucet): Hanzo Faucet is a token distribution service for Hanzo Network (the AI Compute L1 blockchain). It distributes test $AI tokens on both Testnet (Chain ID: 36962) and Mainnet (Chain ID: 36963). The ba... - [Hanzo Identity](/docs/skills/hanzo-identity): Hanzo Identity (`hanzoai/identity`) is a decentralized identity (DID) registration system with Solidity smart contracts and a Next.js frontend. It implements W3C DID identifiers across the Lux/Hanz... - [Hanzo MPC](/docs/skills/hanzo-mpc): Hanzo MPC is a threshold signing service for securely generating and managing cryptographic wallets across distributed nodes without ever exposing the full private key. Written in Go, it implements... - [Hanzo Nchain](/docs/skills/hanzo-nchain): Nchain is a Kubernetes operator for deploying and scaling blockchain nodes. Built with kubebuilder and controller-runtime, it defines custom resources (CRDs) for managing multi-protocol blockchain ... - [Hanzo Network - Distributed AI Agent Topology](/docs/skills/hanzo-network): Hanzo Network enables distributed AI agent execution across heterogeneous devices (M1 MacBooks, NVIDIA GPUs, Linux servers, Raspberry Pis, etc.) with automatic peer discovery, device capability det... - [Hanzo Node - Rust AI Agent Infrastructure](/docs/skills/hanzo-node): Hanzo Node is a Rust-based AI agent infrastructure node that lets you create AI agents without writing code. It provides local AI inference, peer-to-peer networking, MCP tool support, and an HTTP A... - [Hanzo Web3 - Blockchain API for 100+ Chains](/docs/skills/hanzo-web3): Hanzo Web3 is the blockchain infrastructure layer of the Hanzo ecosystem. - [Hanzo Web3 Gateway - Keyless Blockchain Access via x402](/docs/skills/hanzo-web3-gateway): Hanzo Web3 Gateway provides keyless blockchain access for autonomous AI agents. - **Commerce & Finance** - [Hanzo AuthorizeNet-Go](/docs/skills/hanzo-authorizenet): AuthorizeNet-Go is a Go client library for the Authorize.net XML/JSON API. It covers three major API surfaces: AIM (Advanced Integration Method) for payment transactions, CIM (Customer Information ... - [Hanzo Checkout.js](/docs/skills/hanzo-checkout): Checkout.js is an embeddable checkout widget for taking payments and pre-orders on any website. It renders a modal overlay with payment collection (Stripe and PayPal), shipping address, tax/shippin... - [Hanzo Commerce - Multi-Tenant E-Commerce and Billing Platform](/docs/skills/hanzo-commerce): Hanzo Commerce is the core product of Hanzo AI -- a multi-tenant e-commerce platform that powers billing, payments, subscriptions, storefronts, and API usage metering for the entire Hanzo ecosystem... - [Hanzo Commerce - E-Commerce & Payments Platform](/docs/skills/hanzo-commerce-api): Hanzo Commerce is a Go/Gin e-commerce API with SQLite storage, providing products, orders, subscriptions, invoices, usage metering, and multi-currency support (fiat + crypto). - [Hanzo Billing - Subscription and Payment Management Portal](/docs/skills/hanzo-billing): Hanzo Billing is a multi-org billing portal for managing subscriptions, payments, credits, invoices, and usage across the Hanzo ecosystem. Static-exported Next.js 16 app with `@hanzo/ui` components... - [Hanzo Form.js](/docs/skills/hanzo-form): Form.js is a lightweight browser library for automatic form validation and submission. It intercepts native HTML form submit events, emits lifecycle events (init, submit, done), and provides an XHR... - [Hanzo GoChimp3](/docs/skills/hanzo-gochimp): GoChimp3 is a Go client library for the MailChimp API v3.0. It provides typed Go structs and methods for managing audiences (lists), members, campaigns, automations, e-commerce data, templates, seg... - [Hanzo Ledger - Programmable Double-Entry Financial Ledger](/docs/skills/hanzo-ledger): Hanzo Ledger is a programmable double-entry financial ledger written in Go. It provides atomic multi-posting transactions, account-based modeling, and a scriptable DSL called Numscript for expressi... - [Hanzo Numscript](/docs/skills/hanzo-numscript): Numscript is a domain-specific language for modeling complex financial transactions. It provides declarative syntax for multi-party fund transfers with percentage splits, ordered funding sources, o... - [Hanzo Payments - Payment Orchestration Switch](/docs/skills/hanzo-payments): Hanzo Payments is an open-source payment orchestration switch written in Rust. It routes payments across 50+ processors with smart retries, fallback cascading, and unified analytics. Based on Hyper... - [Hanzo Reconciliation](/docs/skills/hanzo-reconciliation): Hanzo Reconciliation is an automated transaction matching engine that compares ledger balances against payment provider data to verify financial consistency and identify discrepancies. It runs as a... - [Hanzo Sign - Open Source Document Signing](/docs/skills/hanzo-sign): Hanzo Sign is an open-source DocuSign alternative for electronic document signing. Turborepo monorepo with a React Router (Remix) + Hono server frontend, tRPC + ts-rest APIs, Prisma ORM, and PDF si... - [Hanzo Treasury](/docs/skills/hanzo-treasury): Hanzo Treasury is a programmable financial infrastructure stack providing a double-entry ledger, payment connectors, virtual wallets, reconciliation, and workflow orchestration. Go monorepo (forked... - [Hanzo Registry - Private Docker Container Registry](/docs/skills/hanzo-registry): Hanzo Registry is a private Docker container registry running Docker Distribution (registry:2) on hanzo-k8s, authenticated via Hanzo IAM token-based auth. It provides a self-hosted alternative to D... - **Identity & Security** - [Hanzo Guard - LLM I/O Safety Layer](/docs/skills/hanzo-guard): Hanzo Guard is a Rust-based LLM I/O sanitization library and toolkit that sits between applications and LLM providers. Detects and redacts PII, blocks prompt injection attacks, enforces rate limits... - [Hanzo IAM - Identity and Access Management Server](/docs/skills/hanzo-iam): Hanzo IAM is the server-side identity and access management service for the Hanzo ecosystem. A Hanzo IAM fork written in Go (Beego framework) with a React admin UI, providing OAuth 2.0/OIDC/SAML/CAS/... - [Hanzo ID - Identity & Authentication](/docs/skills/hanzo-id): Hanzo ID is the unified identity platform for the entire Hanzo/Lux/Zoo ecosystem. - [Hanzo KMS - Key & Secret Management](/docs/skills/hanzo-kms): Hanzo KMS is a centralized secret management platform for the Hanzo ecosystem. Fork of Hanzo KMS with Hanzo branding, Universal Auth, and K8s-native secret sync via KMSSecret CRD. Live at `kms.hanz... - [Hanzo Vault - PCI-Compliant Card Tokenization](/docs/skills/hanzo-vault): Hanzo Vault is a PCI DSS-compliant card tokenization service (CDE - Cardholder Data Environment). - **ML & Research** - [Hanzo ANE - Apple Neural Engine Training](/docs/skills/hanzo-ane): Hanzo ANE enables training neural networks directly on Apple Neural Engine across ALL Apple Silicon (M1+). Reverse-engineered private API for direct ANE access — not just inference but actual gradi... - [Hanzo Candle - Rust ML Framework](/docs/skills/hanzo-candle): Hanzo Candle is a Rust-based machine learning framework — intended fork of HuggingFace candle for high-performance ML inference and training with GPU acceleration (CUDA + Metal). - [Hanzo Engine - Native Rust Inference & Embedding Engine](/docs/skills/hanzo-engine): Hanzo Engine is Hanzo AI's high-performance, Rust-native inference and embedding engine that powers the entire Hanzo ecosystem. - [Zoo Gym - Unified AI Model Training Platform](/docs/skills/hanzo-gym): Zoo Gym is the unified training infrastructure for all ZenLM AI models, built on LLaMA Factory. - [Hanzo Jin - Visual Self-Supervised Learning Framework](/docs/skills/hanzo-jin): Jin is a research-stage visual self-supervised learning framework implementing Joint Embedding Predictive Architectures (JEPA). - [Hanzo Kensho](/docs/skills/hanzo-kensho): Kensho is a 17B parameter image generation foundation model using a Mixture of Experts (MoE) Diffusion Transformer architecture. It generates high-quality images from text prompts at multiple resol... - [Hanzo Koe](/docs/skills/hanzo-koe): Koe is a 1.6B parameter text-to-speech model that directly generates realistic multi-speaker dialogue from text transcripts. It supports two-speaker conversations with speaker tags (`[S1]`, `[S2]`)... - [Hanzo ML](/docs/skills/hanzo-ml): Hanzo ML is a Rust-based minimalist ML framework forked from HuggingFace Candle, optimized for edge AI, quantization, and multimodal inference. It provides the tensor computation layer for the Hanz... - [Hanzo Mugen](/docs/skills/hanzo-mugen): Mugen is a PyTorch framework for deep learning research on audio generation. It provides training and inference code for multiple state-of-the-art generative audio models: text-to-music (MusicGen),... - [Hanzo Sho](/docs/skills/hanzo-sho): Sho is a text diffusion engine that generates text using masked diffusion rather than autoregressive token prediction. The core model (Genjo, 8B parameters) uses a Transformer Encoder with bidirect... - [ZenLM - Next-Generation Local AI Models](/docs/skills/zenlm): ZenLM is a collaboration between Hanzo AI and Zoo Labs Foundation, building AI models that run entirely on your device—no cloud, no subscriptions, no surveillance. - **Data & Messaging** - [Hanzo Analytics - Privacy-Focused Web Analytics](/docs/skills/hanzo-analytics): Hanzo Analytics is a privacy-focused web analytics platform -- an alternative to Google Analytics. Next.js 15 dashboard (port 3000) with Prisma ORM, PostgreSQL/ClickHouse storage, and a Go-based hi... - [Hanzo Database - PostgreSQL, Redis & Vector Storage](/docs/skills/hanzo-database): Hanzo Database covers PostgreSQL (with pgvector), Redis, MongoDB, and MinIO configurations used across the Hanzo ecosystem. - [Hanzo Datastore - Vector Database Integration](/docs/skills/hanzo-datastore): Hanzo Datastore provides a unified vector database abstraction for AI applications — embedding storage, similarity search, and RAG retrieval. - [Hanzo DocDB](/docs/skills/hanzo-documentdb): DocDB is a MongoDB-compatible document database server. It is a proxy that converts MongoDB 5.0+ wire protocol queries to SQL, using PostgreSQL with the DocumentDB extension as the storage engine. ... - [Hanzo Insights - Product Analytics Platform](/docs/skills/hanzo-insights): Hanzo Insights is a full product analytics platform with product analytics, feature flags, session recording, A/B testing, heatmaps, LLM analytics, error tracking, surveys, web an... - [Hanzo KV](/docs/skills/hanzo-kv): Hanzo KV is a Redis-compatible in-memory key-value store used as the caching, streaming, and message broker layer across the Hanzo ecosystem. C codebase built with CMake, ships as `ghcr.io/hanzoai/... - [Hanzo KV Go SDK](/docs/skills/hanzo-kv-go): Go client library for Hanzo KV (Redis/Valkey compatible). Fork of `redis/go-redis` v9 with module path rewritten to `github.com/hanzoai/kv-go/v9`. The Go package name is `redis` -- import the modul... - [Hanzo Logs](/docs/skills/hanzo-logs): Hanzo Logs is a horizontally-scalable, multi-tenant log aggregation system for Hanzo infrastructure. Fork of Grafana Loki. Written in Go. Indexes labels (not full text) for cost-effective log stora... - [Hanzo Metrics](/docs/skills/hanzo-metrics): Hanzo Metrics is a fast, cost-effective time-series database for monitoring AI infrastructure. Fork of VictoriaMetrics. Written in Go. Supports PromQL and MetricsQL queries, multiple ingestion prot... - [Hanzo O11y - Full-Stack Observability Platform](/docs/skills/hanzo-o11y): Hanzo O11y is a full-stack observability platform for logs, metrics, and traces. Go 1.25 backend (Gin/gorilla-mux) with a React 18 + Vite frontend. Uses ClickHouse as the telemetry datastore and Op... - [Hanzo ORM - Go Generics ORM with Auto-Serialization](/docs/skills/hanzo-orm): Hanzo ORM is a Go generics-based ORM with automatic serialization, KV caching, and zero code generation. - [Hanzo PubSub - Event Streaming and Message Queue](/docs/skills/hanzo-pubsub): Hanzo PubSub is a high-performance messaging system for pub/sub, persistent streams, and exactly-once delivery. It is a fork of NATS Server with Hanzo branding and a bundled Kafka-compatible Redpan... - [Hanzo PubSub Go SDK](/docs/skills/hanzo-pubsub-go): Go client library for Hanzo PubSub (NATS compatible). Fork of `nats-io/nats.go` with module path rewritten to `github.com/hanzoai/pubsub-go`. Provides publish/subscribe messaging, request/reply, Je... - [Hanzo Storage](/docs/skills/hanzo-s3): Hanzo Storage is a high-performance, S3-compatible object storage server for AI workloads. Fork of MinIO. This is a full server binary, not a client library. Any S3-compatible SDK (aws-sdk-go, boto... - [Hanzo Search Go SDK](/docs/skills/hanzo-search-go): Go client library for Hanzo Search (Meilisearch compatible). Fork of `meilisearch/meilisearch-go` with module path rewritten to `github.com/hanzoai/search-go`. The Go package name is `meilisearch`.... - [Hanzo Sentry - Error Tracking & Performance Monitoring](/docs/skills/hanzo-sentry): Hanzo Sentry is a self-hosted Sentry 24.2.0 deployment for error tracking and performance monitoring across all Hanzo, Lux, Zoo, and Pars services. It is a fork of getsentry/sentry with a custom Do... - [Hanzo SQL](/docs/skills/hanzo-sql): Hanzo SQL is a PostgreSQL fork with pre-built extensions for AI workloads: pgvector (vector similarity), pg_cron (scheduled jobs), pg_documentdb (MongoDB wire protocol), and PostGIS (geospatial). S... - [Hanzo Storage - S3-Compatible Object Storage](/docs/skills/hanzo-storage): Hanzo Storage is a high-performance, S3-compatible object storage server for AI workloads. It is a fork of MinIO, rebranded and optimized for the Hanzo ecosystem. Written in Go. Live in production ... - [Hanzo Stream](/docs/skills/hanzo-stream): Hanzo Stream is a stateless Kafka wire protocol gateway that translates standard Kafka client requests into NATS JetStream operations against Hanzo PubSub. Go codebase (module `github.com/hanzoai/s... - [Hanzo Vector - High-Performance Vector Search Engine](/docs/skills/hanzo-vector): Hanzo Vector is a high-performance vector search engine for the Hanzo AI platform. It is a full fork of Qdrant v1.17.0, written in Rust, providing dense and sparse vector similarity search with fil... - [Hanzo Vector Go SDK](/docs/skills/hanzo-vector-go): Go client library for Hanzo Vector (Qdrant compatible). Fork of `qdrant/go-client` with module path rewritten to `github.com/hanzoai/vector-go`. Uses gRPC for communication. The main package is `qd... - **Platform & Infrastructure** - [Hanzo Charts](/docs/skills/hanzo-charts): Hanzo Charts is the official Helm chart repository for all Hanzo services and infrastructure. Contains 16 charts covering core services (IAM, KMS, Gateway), AI services (Cloud, Agents, LLM), platfo... - [Hanzo CLI](/docs/skills/hanzo-cli): Hybrid Rust+Node+Python command-line tool providing unified access to all Hanzo services with project scaffolding, local development, deployment, and authentication. - [Hanzo Dataroom](/docs/skills/hanzo-dataroom): Hanzo Dataroom is the open-source DocSend alternative -- a document sharing platform with built-in analytics, custom domains, and secure link-based access. Papermark fork rebranded for the Hanzo ec... - [Hanzo DNS](/docs/skills/hanzo-dns): Hanzo DNS is a CoreDNS fork providing a programmable, plugin-based DNS server for Hanzo infrastructure. Go codebase (module `github.com/coredns/coredns`), ships as a single `coredns` binary. Includ... - [Hanzo Edge - On-Device AI Inference Runtime](/docs/skills/hanzo-edge): Hanzo Edge is an on-device AI inference runtime for running Zen models and any GGUF model locally on macOS, Linux, Web (WASM), and embedded devices. Zero cloud dependency, full data privacy, zero n... - [Hanzo Extract](/docs/skills/hanzo-extract): Content Extraction & Sanitization - [Hanzo Functions](/docs/skills/hanzo-functions): Hanzo Functions is a Kubernetes-native serverless platform for event-driven workloads with GPU support. Go codebase (module `github.com/fission/fission`, Fission fork), runs as a set of K8s control... - [Hanzo Gateway - API Gateway for Hanzo and Lux Networks](/docs/skills/hanzo-gateway): Hanzo Gateway is a high-performance API gateway built on KrakenD/Lura that routes 147+ endpoints across production clusters. It serves as the unified API entry point for all Hanzo (`api.hanzo.ai`) ... - [Hanzo HKE](/docs/skills/hanzo-hke): Managed Kubernetes Engine - [Hanzo Ingress - Cloud-Native L7 Reverse Proxy and Load Balancer](/docs/skills/hanzo-ingress): Hanzo Ingress is a Kubernetes-native L7 reverse proxy and load balancer that serves as the front door for all Hanzo production traffic. Built in Go (Traefik fork), it watches Kubernetes Ingress res... - [Hanzo Log](/docs/skills/hanzo-log): Hanzo Log is a high-performance, zero-allocation structured logging library for Go. Based on zerolog with a dual API: a zero-allocation chaining style and a geth-compatible variadic style. Both sha... - [Hanzo Operator](/docs/skills/hanzo-operator): Hanzo Operator is a unified Kubernetes operator that manages all Hanzo production infrastructure declaratively via 7 CRDs under the `hanzo.ai/v1alpha1` API group. Built with Kubebuilder v4 and cont... - [Hanzo Platform - Cloud PaaS for AI Applications](/docs/skills/hanzo-platform): Hanzo Platform is a Kubernetes-native PaaS (Platform as a Service) for deploying AI applications, APIs, and services. - [Hanzo Relay](/docs/skills/hanzo-relay): Hanzo Relay (crate name: `hanzo-relay`, internally `hanzo-tunnel`) is a Rust library that connects any local Hanzo app (dev, node, desktop, bot, extension) to the cloud relay at `api.hanzo.ai` for ... - [Hanzo REPL](/docs/skills/hanzo-repl): Interactive MCP Testing Environment - [Hanzo Runtime - Secure AI Code Execution Sandbox](/docs/skills/hanzo-runtime): Hanzo Runtime is a secure, isolated sandbox environment for executing AI-generated code. Sub-90ms sandbox creation, OCI/Docker-compatible, with programmatic File, Git, LSP, and Execute APIs. Multi-... - [Hanzo Skill](/docs/skills/hanzo-skill): Hanzo Skill (`@hanzo/skill`) is a TypeScript CLI tool for installing, managing, and distributing AI agent skills. It clones skill repositories to `~/.hanzo/skills/` as the canonical source of truth... - [Hanzo Stack - Full Integrated Development Environment](/docs/skills/hanzo-stack): Hanzo Stack provides the complete integrated development environment for running all Hanzo services locally. - [Hanzo Terraform Provider](/docs/skills/hanzo-terraform): The Hanzo Terraform Provider is a Stainless-generated Terraform SDK for managing Hanzo AI resources via Infrastructure as Code. Built on the HashiCorp Terraform Plugin Framework, it wraps the Hanzo... - [Hanzo Tunnel - Cloud Tunnel Client for Remote Agent Control](/docs/skills/hanzo-tunnel): Hanzo Tunnel is a Rust library and Python agent bridge that connects local Hanzo app instances (dev machines, bots, nodes) to the cloud control plane at `app.hanzo.bot`. It provides WebSocket-based... - [Hanzo Universe](/docs/skills/hanzo-universe): Production Kubernetes Infrastructure - [Hanzo VM](/docs/skills/hanzo-vm): Hanzo VM is an open-source cloud operating system and virtual machine management platform built with Go (Beego framework) and React. Go module `github.com/hanzoai/vm`, ships as a single `server` bi... - [Hanzo ZAP](/docs/skills/hanzo-zap): Hanzo ZAP (`hanzoai/zap`) is a Go sidecar that bridges the ZAP protocol to backend infrastructure services. It runs as a sidecar container alongside databases and caches, translating ZAP protocol c... - [Hanzo Zrok](/docs/skills/hanzo-zrok): Hanzo Zrok is a zero-trust sharing platform built on top of Hanzo ZT (OpenZiti). It lets users securely share web services, files, and network resources through firewalls and NAT without any networ... - [Hanzo ZT](/docs/skills/hanzo-zt): Hanzo ZT is the zero-trust network overlay fabric that powers Hanzo's secure networking infrastructure. It provides a programmable, scalable mesh network with identity-based access control, end-to-... - **Products** - [Hanzo Chat - AI Chat Application](/docs/skills/hanzo-chat): Hanzo Chat (`@hanzochat/chat`) is a full-featured AI chat application -- a LibreChat v0.8.3-rc1 fork providing a web UI for conversing with AI models, managing conversations, using agents, and inte... - [Hanzo Cloud - AI Cloud Dashboard & Management](/docs/skills/hanzo-cloud): Hanzo Cloud is the AI provider management platform — Go 1.26 Beego MVC backend with React frontend (CRA via CRACO, .js + .less), PostgreSQL database, and integrations for 30+ AI providers. Fork of ... - [Hanzo Console - AI Observability and Prompt Management](/docs/skills/hanzo-console): Hanzo Console is the observability and prompt management layer for AI applications. - [Hanzo LLM Gateway](/docs/skills/hanzo-llm-gateway): Unified proxy that routes requests to 100+ LLM providers through a single OpenAI-compatible API with smart routing, cost tracking, and provider fallback. - **SDKs & Libraries** - [Hanzo Go SDK](/docs/skills/go-sdk): Stainless-generated Go client library for the Hanzo AI API with full type safety, context-aware requests, streaming, auto-pagination, and auto-retry across 187 endpoints. - [Hanzo Base - Open Source Backend for Any App](/docs/skills/hanzo-base): Hanzo Base is an open source Go backend that provides a complete application backend in a single binary. It includes embedded SQLite and PostgreSQL databases with realtime subscriptions, built-in f... - [Hanzo OpenAPI](/docs/skills/hanzo-openapi): Hanzo OpenAPI is the canonical OpenAPI 3.1.0 specification for all 26 Hanzo Cloud services. One master spec (`hanzo.yaml`) plus per-service specs, shared schemas, and everything needed to generate ... - [Hanzo SDK](/docs/skills/hanzo-sdk): Hanzo SDK is a unified multi-language SDK and CLI (`@hanzo/cli`) that wraps Python, TypeScript, Rust, and Go implementations into a single `hanzo` command. Published as an npm package with optional... - [Hanzo tRPC OpenAPI](/docs/skills/hanzo-trpc-openapi): `@hanzo/trpc-openapi` is a TypeScript library that generates OpenAPI 3.x documents from tRPC v11 routers and provides HTTP adapters to serve tRPC procedures as REST endpoints. Published on npm as `... - [Hanzo JavaScript SDK](/docs/skills/js-sdk): TypeScript-first client library for the Hanzo AI API, generated by Stainless with full type safety, streaming, auto-retry, and support for Node.js, Bun, Deno, and browsers. - [Hanzo Python SDK](/docs/skills/python-sdk): Stainless-generated Python client library for the Hanzo AI API with full type safety, async support, streaming, auto-pagination, and auto-retry across 187 endpoints. - [Hanzo Rust SDK](/docs/skills/rust-sdk): Full Rust infrastructure SDK with 14 active crates covering agent framework, MCP implementation, post-quantum cryptography, AI safety, and multi-backend proxy. - **Research & Governance** - [Hanzo Improvement Proposals (HIPs)](/docs/skills/hanzo-hips): Hanzo Improvement Proposals (HIPs) - **Research** - [Research Papers](/docs/research): Technical whitepapers on Hanzo AI infrastructure, the Zen frontier model family, post-quantum cryptography, and defense applications. - **Open Source** - Projects: Documentation for all Hanzo projects. - [Projects](/docs/projects): Aggregated documentation across Hanzo organizations. - hanzoai: Projects in the hanzoai organization. - [hanzoai](/docs/projects/hanzoai): Projects in the hanzoai organization. - Arc: Kubernetes controller for GitHub Actions self-hosted runners - [Arc](/docs/projects/hanzoai/arc): Kubernetes controller for GitHub Actions self-hosted runners - Authz: Authorization engine (fork of casbin/casbin v2) - [Authz](/docs/projects/hanzoai/authz): Authorization engine (fork of casbin/casbin v2) - Base: Hanzo Base - Backend-as-a-Service with realtime and auth - [Base](/docs/projects/hanzoai/base/index): Hanzo Base - Backend-as-a-Service with realtime and auth - Chat: AI chat with MCP integration and multi-provider support - [Chat](/docs/projects/hanzoai/chat/index): AI chat with MCP integration and multi-provider support - Ci: Reusable CI/CD: build/test/deploy any repo from its hanzo.yml on arc - [Index](/docs/projects/hanzoai/ci) - Clickhouse Go Mock: Documentation for Clickhouse Go Mock. - [Clickhouse Go Mock](/docs/projects/hanzoai/clickhouse-go-mock): Documentation for Clickhouse Go Mock. - Cms: Hanzo CMS — brand-neutral white-label headless CMS (Payload fork) on Base/SQLite, SeaweedFS S3, and IAM SSO. All packages under @hanzo/cms scope. - [Cms](/docs/projects/hanzoai/cms): Hanzo CMS — brand-neutral white-label headless CMS (Payload fork) on Base/SQLite, SeaweedFS S3, and IAM SSO. All packages under @hanzo/cms scope. - Core Networkmanagement: Networkmanager built with coreDNS and coreDHCP with web gui - [Core Networkmanagement](/docs/projects/hanzoai/core-networkmanagement): Networkmanager built with coreDNS and coreDHCP with web gui - Dataroom: Papermark is the open-source DocSend alternative with built-in analytics and custom domains. - [Dataroom](/docs/projects/hanzoai/dataroom): Papermark is the open-source DocSend alternative with built-in analytics and custom domains. - Datastore: ClickHouse® is a real-time analytics database management system - [ClickHouse Documentation](/docs/projects/hanzoai/datastore/index): Placeholder landing page while the Mintlify migration is in progress. - Deepspec: DeepSpec (DSpark/DFlash/Eagle3 draft training) + Hanzo V4 pipeline — fork of deepseek-ai/DeepSpec - [Deepspec](/docs/projects/hanzoai/deepspec): DeepSpec (DSpark/DFlash/Eagle3 draft training) + Hanzo V4 pipeline — fork of deepseek-ai/DeepSpec - Esign: The Open Source DocuSign Alternative. - [Esign](/docs/projects/hanzoai/esign): The Open Source DocuSign Alternative. - Expr: Expression language and expression evaluation for Go - [Expr](/docs/projects/hanzoai/expr): Expression language and expression evaluation for Go - Extension: 🧩 Hanzo Extension: IDE plugin for VS Code compatible IDEs. - [Index](/docs/projects/hanzoai/extension/index) - Forum: A platform for community discussion. Free, open, simple. - [Forum](/docs/projects/hanzoai/forum/index): A platform for community discussion. Free, open, simple. - Frappe: Low code web framework for real world applications, in Python and Javascript - [Frappe](/docs/projects/hanzoai/frappe): Low code web framework for real world applications, in Python and Javascript - Gateway: Hanzo Gateway — KrakenD-based high-performance API gateway. Routes 147+ endpoints at api.hanzo.ai with rate limiting, auth forwarding, CORS, circuit breakers, telemetry. - [Gateway](/docs/projects/hanzoai/gateway/index): Hanzo Gateway — KrakenD-based high-performance API gateway. Routes 147+ endpoints at api.hanzo.ai with rate limiting, auth forwarding, CORS, circuit breakers, telemetry. - Go Fuse: FUSE bindings for Go - [Go Fuse](/docs/projects/hanzoai/go-fuse): FUSE bindings for Go - Goa: Pure-Go polyglot embedding: run Go, JS/TS (goja), Python (gpython), Rust/WASM (wazero) as goroutines in one static binary. Unifies Hanzo cloud services. - [Index](/docs/projects/hanzoai/goa) - Goexif: EXIF decoder for Go — Hanzo fork of goexif (BSD-2-Clause). Module: github.com/hanzoai/goexif - [Index](/docs/projects/hanzoai/goexif) - Govaluate: Documentation for Govaluate. - [Govaluate](/docs/projects/hanzoai/govaluate): Documentation for Govaluate. - Helpdesk: Hanzo Help Center — Frappe Helpdesk fork (Base/SQLite, IAM SSO). Second Frappe app proving one-Frappe-core → all-Frappe-apps. - [Helpdesk](/docs/projects/hanzoai/helpdesk): Hanzo Help Center — Frappe Helpdesk fork (Base/SQLite, IAM SSO). Second Frappe app proving one-Frappe-core → all-Frappe-apps. - Helper: Hanzo helper CLI: configure Claude Code, Claude Desktop, and Codex to use Hanzo AI - [Index](/docs/projects/hanzoai/helper) - Iam: Hanzo IAM — OAuth2/OIDC identity provider (Go, JWKS issuer) — multi-tenant with per-org SQLite isolation - [Iam](/docs/projects/hanzoai/iam/index): Hanzo IAM — OAuth2/OIDC identity provider (Go, JWKS issuer) — multi-tenant with per-org SQLite isolation - Ingress: Hanzo Ingress — Traefik fork with hanzoai/static + hanzoai/gateway integration for k8s native deployments - [Ingress](/docs/projects/hanzoai/ingress/index): Hanzo Ingress — Traefik fork with hanzoai/static + hanzoai/gateway integration for k8s native deployments - Insights: Product analytics and feature flags - [Insights](/docs/projects/hanzoai/insights/index): Product analytics and feature flags - Jube Fork: Open source AML and Fraud Detection using Machine Learning for Real-Time Transaction Monitoring - [Jube Fork](/docs/projects/hanzoai/jube-fork): Open source AML and Fraud Detection using Machine Learning for Real-Time Transaction Monitoring - Kms: Hanzo KMS — Go server wrapping luxfi/kms primitives - [Kms](/docs/projects/hanzoai/kms/index): Hanzo KMS — Go server wrapping luxfi/kms primitives - Kv: Ultra-fast key-value store with Redis API compatibility - [Kv](/docs/projects/hanzoai/kv/index): Ultra-fast key-value store with Redis API compatibility - Migrate: Database migrations. CLI and Golang library. - [Migrate](/docs/projects/hanzoai/migrate): Database migrations. CLI and Golang library. - Ml: Documentation for Ml. - [Ml](/docs/projects/hanzoai/ml/index): Documentation for Ml. - Nodejs: Canonical Node 24 + sqlite3 base image for all Hanzo Node services - [Nodejs](/docs/projects/hanzoai/nodejs): Canonical Node 24 + sqlite3 base image for all Hanzo Node services - O11y: SigNoz is an open-source observability platform native to OpenTelemetry with logs, traces and metrics in a single application. An open-source alternative to DataDog, NewRelic, etc. 🔥 🖥. 👉 Open source Application Performance Monitoring (APM) & Observability tool - [O11y](/docs/projects/hanzoai/o11y): SigNoz is an open-source observability platform native to OpenTelemetry with logs, traces and metrics in a single application. An open-source alternative to DataDog, NewRelic, etc. 🔥 🖥. 👉 Open source Application Performance Monitoring (APM) & Observability tool - O11y Foundry: Foundry is a centralized hub for SigNoz installation configurations and deployments: integrations for install. Select yours, configure, and run SigNoz. - [Index](/docs/projects/hanzoai/o11y-foundry) - Otel Collector: SigNoz distro for OpenTelemetry Collector - [Otel Collector](/docs/projects/hanzoai/otel-collector): SigNoz distro for OpenTelemetry Collector - Paas Demo: Documentation for Paas Demo. - [Paas Demo](/docs/projects/hanzoai/paas-demo): Documentation for Paas Demo. - ROCm: AMD ROCm™ Software - GitHub Home - [ROCm](/docs/projects/hanzoai/ROCm): AMD ROCm™ Software - GitHub Home - Rocm Rs: Hanzo fork of rocm-rs — cross-platform (Linux + Windows/MSVC) ROCm bindings for gfx1151: portable enum/status types, edition-2024 unsafe blocks, gated amdgcn GPU-sort kernel. - [Index](/docs/projects/hanzoai/rocm-rs) - Runtime - [Runtime](/docs/projects/hanzoai/runtime): Documentation for Runtime. - S3: Hanzo Space — S3-compatible object storage for AI infrastructure - [S3](/docs/projects/hanzoai/s3/index): Hanzo Space — S3-compatible object storage for AI infrastructure - S3 Cli: Hanzo S3-compatible storage CLI - [S3 Cli](/docs/projects/hanzoai/s3-cli): Hanzo S3-compatible storage CLI - Signoz: SigNoz is an open-source observability platform native to OpenTelemetry with logs, traces and metrics in a single application. An open-source alternative to DataDog, NewRelic, etc. 🔥 🖥. 👉 Open source Application Performance Monitoring (APM) & Observability tool - [Signoz](/docs/projects/hanzoai/signoz): SigNoz is an open-source observability platform native to OpenTelemetry with logs, traces and metrics in a single application. An open-source alternative to DataDog, NewRelic, etc. 🔥 🖥. 👉 Open source Application Performance Monitoring (APM) & Observability tool - Signoz Otel Collector: SigNoz distro for OpenTelemetry Collector - [Signoz Otel Collector](/docs/projects/hanzoai/signoz-otel-collector): SigNoz distro for OpenTelemetry Collector - Social: 📨 Hanzo Social — agentic social media scheduling 🤖 - [Social](/docs/projects/hanzoai/social): 📨 Hanzo Social — agentic social media scheduling 🤖 - Sql: Hanzo SQL - PostgreSQL with pgvector for AI workloads - [Sql](/docs/projects/hanzoai/sql/index): Hanzo SQL - PostgreSQL with pgvector for AI workloads - Sqlite3: Go bindings to SQLite using wasm2go - [Sqlite3](/docs/projects/hanzoai/sqlite3): Go bindings to SQLite using wasm2go - Studio: Hanzo Studio — Visual AI Engine - [Studio](/docs/projects/hanzoai/studio/index): Hanzo Studio — Visual AI Engine - Studio Frontend: Hanzo Studio frontend - [Studio Frontend](/docs/projects/hanzoai/studio-frontend): Hanzo Studio frontend - Vfs: S3-backed virtual block filesystem with PQ encryption — unlimited write storage for stateful services - [Vfs](/docs/projects/hanzoai/vfs): S3-backed virtual block filesystem with PQ encryption — unlimited write storage for stateful services - Video: World's first open-source, agentic video production system. 12 pipelines, 52 tools, 500+ agent skills. Turn your AI coding assistant into a full video production studio. - [Video](/docs/projects/hanzoai/video): World's first open-source, agentic video production system. 12 pipelines, 52 tools, 500+ agent skills. Turn your AI coding assistant into a full video production studio. - World: World Monitor - [World](/docs/projects/hanzoai/world): World Monitor - Zen Dub: Zen Dub - Real-time high-quality lip-sync model - [Zen Dub](/docs/projects/hanzoai/zen-dub): Zen Dub - Real-time high-quality lip-sync model