Try it

Pick a scenario, read its rules, change the request and see what the engine decides. Everything runs in this page: nothing to install, nothing sent anywhere.

Step 1: Pick a scenario

Denied by a server-only rule the transfer ruleset inherits from its parent.

Step 2: Read the rules

The engine evaluates payments-transfer.ruleset.yaml. It extends acme.org.base, so those rules apply too, and it may only tighten them.

  1. acme.payments.transferevaluated
  2. extendsacme.org.baseparent

Step 3: Edit the request

Channel

Server runs everything the API enforces. Client runs only what the browser is allowed to see: server-only rules are hidden.

Step 4: Run it

Evaluate runs this request against the rules. Check rules validates the YAML, runs the load checks and every golden test.

Shortcuts
Ctrl+Enter
Evaluate (in any editor)
Ctrl+Shift+Enter
Check rules
← →
Move between file tabs

On a Mac, use ⌘ instead of Ctrl.

Step 5: Read the result

Starting the engine...

Try this next

0 of 2 done
  • Switch to the client channel (not done yet)

    The blocked-country rule is server-only, so the browser never sees it: ORG-TRF-001 disappears and the transfer is allowed.

  • Send the transfer to Germany ("country": "DE") (not done yet)

    Even on the server, where every rule runs, nothing blocks it: allowed, and the fee is still computed.

What to notice in this scenario

The decision is deny, and the finding ORG-TRF-001 does not come from the transfer ruleset at all: it comes from acme.org.base, the organisation ruleset that payments-transfer extends (open its tab). Its rule is locked and server-only (enforcement: server), so switch the channel to client and evaluate again: the browser never receives the list of blocked countries, and the same request shows no finding there. The fee of 7.5 is a computed value from a compute rule.

From examples/contracts/payments-transfer.ruleset.yaml, golden test "blocked country is denied on the server".

How this works

The engine runs in this page, in a Web Worker. It is the TypeScript runtime, which passes the same conformance suite as every other engine, so the answer is the one Java, Go, Python and the rule-cascade command give.

Like rule-cascade check, the playground registers the three conformance operators (x-luhn, x-test-reverse, x-test-sum), and Check rules runs every golden test in the tests of each ruleset. A ruleset names its parents in extends and its entity schema in $ref: both are found among the tabs by id and by file name.

To run the same thing on your machine, download the command and follow the quickstart.