How it works
You say what your product has to do. Your agent writes it on Typestate, in English you can read. Typestate checks it, tests it, runs it at your address, and waits for your yes before your customers see a change.
Seven steps, from the first sentence to Live.
Connect your agent, once
Typestate is an MCP server. You add it to the agent you already use, in one sentence, and from then on the agent builds on Typestate without you leaving the tool you are in.
Add the Typestate MCP server at https://mcp.typestate.com/mcpWaiting for your agent
Paste the sentence into Claude, ChatGPT or Cursor.
This turns green by itself when the agent calls.
Connected
Claude Code is connected, with 87 tools.
Tell it what your product has to do.
Say what it has to do
Your agent writes each flow as a few sentences of English: what comes in, what it refuses and why, what it stores and what comes back. The record types it touches are declared with their fields and rules, so a wrong value is refused by name.
This shop is invented. The rules on it are the kind a real business has.
Place an order
Given a product and a quantity, place an order for the signed-in customer.
If fewer are in stock than asked for, refuse and say how many are left.
Otherwise store the order, take the quantity off the stock, and set its status to placed.
Answer with the order's reference and its total.
OrderThe record type it writes, with what each field accepts
referencetext, set by the platform, no two alikecustomerbelongs to the signed-in customerquantitya whole number, at least 1totalmoney, always therestatusplaced, shipped or refunded
Typestate checks every sentence
Before a flow answers anybody, five things happen to it, and three of them can stop it. You never see the code, and the platform accepts none from you, from your agent or from us.
- It becomes codeThe platform writes the code that does what the sentences say.
- The code is checkedEvery line is checked. A fault gets one repair round, and if that fails the draft stops with the reason in plain English.can stop it
- It is testedThe platform writes tests in your customer's words and runs them. A flow whose tests fail cannot reach Live, and nobody can turn that off.can stop it
- It is read backA second reading sees only the code and says what it does. Where it differs from your English you get a warning.
- You approve itLive runs only what a person has read and said yes to.can stop it
Something is wrong
Place an order did not pass its tests.
1 of 8 failed: "an order for more than is in stock is refused" expected a refusal, and the flow stored the order.
Try it in Sandbox
Every service has a Sandbox at a real address, with its own data. Your agent releases to it as often as it likes, with nobody's approval, and every call is recorded: what came in, each step, and what went out.
What came in
POST /orders
{
"product": "mug-blue",
"quantity": 2
}Each sentence, with its time
What went out
201 Created
{
"reference": "ORD-1043",
"total": "24.00"
}A call that is refused names the sentence that refused it.
Read the change
An edit lands on a draft. Before it reaches Live you read what runs now next to what waits, line for line, in the same English. The database work and any data a change would lose are shown beside it.
Live runs now
Given a product and a quantity, place an order for the signed-in customer.
If fewer are in stock than asked for, refuse and say how many are left.
Waits for your yes
Given a product and a quantity, place an order for the signed-in customer.
If fewer are in stock than asked for, refuse, say how many are left, and offer to hold the rest for 7 days. changed
A customer with 3 orders or more pays no delivery. added
The yes is held against a fingerprint of exactly what was on the screen. Change anything after it and the release is refused, because the yes no longer describes what would go out.
Go Live when it is ready
Live is the address your customers use, with its own data. The button to go there stays grey until every check is done, and each open check says how to close it.
Before Live2 open
All 8 tests pass09:02
shop.example.com answersneeds 1 DNS record
1 change waits for your yesread it
Go Live
Before LiveAll done
All 8 tests pass09:02
shop.example.com answers09:20
Every change has your yes09:31
Go Live
It runs on its own
Once it is Live, nobody sizes a server or starts a job. Work on a clock runs on time, more people get more of it, and everything below comes with every service on the first day.
Today, every timer on one line
ranstill to comefailednow
- Accounts and sign-inPeople make accounts and sign in. A record can belong to one of them.
- The databaseStorage, and the changes to it as your record types grow. Nobody writes a migration.
- FilesPhotos, PDFs and anything people upload, kept on a record and served back.
- TimersA flow that runs every night, every hour, or when you say.
- Other systemsStripe, email, anything with an API. The keys are kept on Typestate.
- Rate limits and accessHow often each caller may call, and which sites may call at all.
- Two environmentsSandbox to build in and Live for your customers, with separate data.
- ScalingMore people arrive and more of it runs.
- The record of every callWhat came in, what it stored, what it refused and what it sent.
Where it runs
Your flows run on Cloudflare, close to whoever called them, with a database of their own for each service and each environment.
Every call is recorded, including each call your backend made to another system, and you can send one of those again. A flow that did something strange last Tuesday is worked out from its own record, not from a guess.
Tell your agent one thing your product has to do. It can answer at a real address today. Free to start. No card.