Learn by doing
Developer articles
Security decisions, integration patterns, and operational guidance for dependable Coldvio agents.
Security
Designing safe customer access for AI agents
Why Coldvio uses browser PKCE, purpose-bound agent tokens, a narrow API, and confirmation gates instead of reusing dashboard sessions.
Patterns
Building reliable Coldvio MCP workflows
A practical pattern for separating discovery, proposal, confirmation, execution, and verification in agent conversations.
Operations
Why headless agents are deferred in v0.1
The credential boundary that keeps v0.1 local until Coldvio ships audited, scoped, revocable provisioning.