Reflex

Jev (TypeSafe System One) as a pre-execution gate

Rules settle what they cover without any API call. For the rest, Reflex can send one request to TypeSafe Jev, a small System One model that answers typed questions about the command, and your policy.json turns the answers into pass, ask or deny. The local engine needs no key; Jev is used after reflex setup --engine jev, or when a TypeSafe key is present.

Install: npx @ursuciprian/reflex setup starts with local rules in shadow mode, no account or key. Plugins for Claude Code, Codex CLI and opencode: setup guide.

What is TypeSafe Jev (System One)?

Jev is TypeSafe's small System One model: it answers typed questions (probabilities, scores and choices) about a piece of state, through TypeSafe's System One API. For each command the rules do not settle, Reflex sends one request with six questions (mutates, blast, env, exfil, on_task, injection; eight with a task envelope), and your policy.json turns the answers into pass, ask or deny. The pinned model is jev-1.13.0; on the tool gate golden set it labelled all 97 commands as expected with 0 misses. Keys come from the TypeSafe console.

See: how a command is decided, TypeSafe docs.

Jev vs Laya: which engine should I use?

Use Jev for decisions; Laya is experimental and measured below Jev on every golden set. Laya runs a Laya checkpoint on 127.0.0.1, so nothing leaves the machine and a call costs nothing, with a tool gate p50 of 125 ms on an Apple M5 Max against Jev's 300 to 330 ms over the network. On the tool gate golden set Laya got 64 of 97 commands right with 33 over-strict (Jev 97, 0, 0), and on the injection golden set precision 54 % against 97 %. Use Laya to run fully offline in shadow mode; for keyless enforcement, the local engine is the recommended choice.

See: Jev vs Laya, head to head, GUIDE: measured against Jev.

Engines: local rules and TypeSafe Jev (System One)

Local and hosted operation

New setup uses --engine local. Deterministic shell checks and path/keyword instruction matches run without TypeSafe. An unknown command produces ask: enforce requires human review, while shadow logs it and leaves the host's permissions in charge. In the autonomous profile that ask goes to System 2 first (keyless autonomy). Local operation does not reuse cached Jev answers, spawn background classifiers, classify subgoals or make semantic instruction calls. The shared Jev client rejects hosted requests while local; the LiteLLM callback leaves model selection unchanged. A separate LiteLLM container needs the same configuration or REFLEX_ENGINE=local.

--engine laya (experimental) asks Jev's questions of a Laya checkpoint served on this machine: nothing leaves it. Measured far below Jev on every golden set; see Laya.

--engine jev enables the existing hosted behavior below. Older direct hook installations (a Keychain item or an agent record in config.json) retain Jev until an engine is selected; with no settings at all the gate uses local; reflex setup records the choice. Defaults are bundled, with durable user overrides under ~/.config/reflex/tool-gate/; reflex status shows the active policy path.

reflex doctor runs local synthetic decision checks in a disposable state directory. These probes do not count as live activation. reflex status separately reports the last real pre-execution hook event and whether it matches the latest installation and settings. The heartbeat is local operational evidence, not proof against an agent that can modify files. Native dialog behavior and host trust must also be checked in the agent itself.

1. Start locally, or enable hosted classification

New reflex setup installations use the local engine: no account, API key, or TypeSafe requests. Rules and deterministic instruction matches work locally. Unknown commands ask in enforce mode; in shadow mode that recommendation is logged while the host's permissions apply. Hard rules still enforce in shadow. Subgoal classification, semantic instruction selection, model routing and context classification require Jev. Native Windows setup is unsupported; run both the agent and Reflex inside WSL.

For hosted classification, choose reflex setup --engine jev and get a TypeSafe API key:

Reflex calls TypeSafe's System One API with the Jev model. From the official quick start:

  1. Sign in to the TypeSafe console: https://console.typesafe.ai/playground

  2. Create an API key on the keys page: https://console.typesafe.ai/keys

  3. Check it works:

    export TYPESAFE_API_KEY=...   # paste the key; do not commit it anywhere
    curl -s -X POST https://api.typesafe.ai/v1/systemone \
      -H "Authorization: Bearer $TYPESAFE_API_KEY" -H "Content-Type: application/json" \
      -d '{"state": "rm -rf build/", "model": "jev-1.13.0",
           "questions": {"destructive": {"type": "noul", "instructions": "Does this shell command delete data?"}}}'

    You should get {"model": "...", "answers": {"destructive": {"type": "noul", "noul": 0.9...}}, "usage": {...}}. 401 means the key is wrong; 429 / 529 mean rate-limited or overloaded (retry shortly).

Reference: HTTP API, models and limits (currently jev-1.13.0, 64k tokens per request, 1,200 requests/minute), legal / data processing.

Where to keep the key

Hooks and plugins inherit the environment the agent was started with. Either:

Never put the key in settings.json, the repo, or shell history.