Skip to content
Vendor.sh

Theme

Palette

Your own colour

Saved for this browser, on every page.

FAQ

Questions, answered honestly.

Including the answers that are “no”. If yours is missing, ask us and we will add it.

Questions, answered honestly.

Product

5 questions

What is Vendor.sh?

A workspace for building agents and workflows, running them against real systems, and seeing every step, cost and failure as it happens. Your product reaches that work through a versioned API.

Do I install Vendor.sh inside each application?

No. Vendor.sh runs as one platform. Your applications connect to the workflows you release.

Can I build a workflow visually?

Yes. Arrange agents, decisions, tools, knowledge, reviews, and results on one canvas.

Can I start from a template?

Yes. The template catalogue publishes checked agents, workflows and tools. Installing one copies it into your own workspace as a draft you own.

Can I return to an earlier release?

Yes. You can move a live environment back to a release that served it before.

Integration

6 questions

How does my backend call a workflow?

It sends a POST to the deployment on the versioned API with a limited service key. Long work answers 202 with a queued run you can follow by events or by reading the run.

Do I need an SDK?

No. It is HTTPS and JSON, described by an OpenAPI 3.1 contract at /openapi.json. You can generate a PHP, Laravel, TypeScript or Python client from it if you prefer one.

What happens if my request is retried?

Send an Idempotency-Key with each intent. A retried request with the same key returns the original run instead of starting a second one.

Where is the exact API contract?

At /openapi.json, with the guides at /docs. Both are public.

Can another AI tool use a Vendor.sh workflow?

Yes. You can expose an approved release as an authenticated remote MCP tool.

Can I place a workflow inside my product?

Yes. A workflow embed sits inside your own pages on a session token, and the visitor stays anonymous.

Billing

4 questions

What counts as a run?

One execution of a deployed workflow or agent, from the request that starts it to its final status. The steps inside it do not count separately.

Can I use my own provider key?

Yes. Choose “Your key” for a provider and that provider bills you for model usage. A call on your key creates no managed provider debit on your Vendor.sh invoice.

What happens at my plan’s limit?

A run is refused rather than queued indefinitely, and the refusal names the limit. Raise the plan, or add a credit pack for managed usage.

Can I inspect workflow cost?

Yes. Cost & usage records each call with its provider, its route and its cost, and keeps managed spend separate from your-key usage.

Trust

5 questions

Do you hold a compliance certification?

No. We do not claim SOC 2, ISO 27001, HIPAA or PCI DSS. The security page lists the controls we have built and the thing that proves each one.

Can another workspace see my data?

No. Every query is scoped to a workspace, and a token cannot move to another workspace through a changed URL. A sweep test asserts it across every public route.

Can a sensitive tool require approval?

Yes. A workflow can pause until an eligible reviewer approves or rejects the request, and the decision stays attached to the run.

Do public templates contain credentials?

No. Public previews and installed packages exclude credentials, URLs, schemas and private identifiers.

How do I report a vulnerability?

Use the contact form and put “Security” in the first line. Please keep it private until we have answered.

Ask the question this page does not answer.

Describe the application, the provider choice and the connection you need.

A person reads it and replies to the email you gave