Documentation
Everything you need to hire, install, and run AI agents on CoreDhristi, and to list, sell, and get paid as a creator. For anything not covered here, ask CoreDhristi AI (bottom-right) or email support@coredhristi.com.
Installation flow at a glance
One picture, two sides of the marketplace: how a developer lists an agent on the left, and how a company pays for and installs it on the right. The steps below cover each side in detail.
npx @coredhristi/cli install CD-XXXXXXXXOn your own server. Downloads the code, sets it up, in about 30 seconds.For Companies: hire and run an agent
Browsing is free and needs no login. When you find an agent that fits, subscribe to it from its listing page. Indian buyers pay in INR via Razorpay (UPI, cards, netbanking); international buyers pay in USD, EUR, or GBP via Stripe. There is no platform subscription fee: you pay only the per-agent price the creator set, billed monthly or yearly per agent, plus a service fee at checkout (4% in India, 6% internationally) that covers payment processing, the security review, and support. The fee is shown as its own line before you pay and on your receipt. Subscriptions are access-based, so your price is the same however much you use the agent in a month.
After payment you get a license key, the agent's code installs on YOUR server with one command, and the agent verifies your subscription every time it starts. Cancel any time from Dashboard, Billing; a 7-day self-serve refund window applies on eligible purchases (see the Terms).
A monthly or yearly subscription renews manually by default - you come back and re-checkout each period. If you pay via Razorpay (India), you can optionally turn on auto-renew from Dashboard, Billing so the same price is charged automatically each period until you cancel; you authorize it once on Razorpay's own page, and nothing is charged until you complete that step. International (Stripe) subscriptions already auto-renew by default with no separate opt-in - you will only ever see one of the two options per agent, never both.
Every hired agent also has a downloadable AI governance report (Dashboard, My Agents, on each agent) - a printable summary of its scan verdict and score, license terms, hire date, and whether auto-renew is currently on, meant as supporting evidence for your own AI-governance or compliance file. It is free with every hire and never claims a formal certification like ISO 42001 or EU AI Act compliance on your behalf.
License keys and installation
Where is my license key?
Your key (it starts with CD-) is shown once on the purchase screen and emailed to you. Afterwards it is masked for security; find it under Dashboard, My Agents. Lost it? Use Regenerate in Dashboard, Billing (limited to 3 per day) - the old key stops working and a new one is emailed to you.
Install the agent
npx @coredhristi/cli install CD-XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXThis downloads the agent's code into the current folder and writes your key into a local .env file as COREDHRISTI_LICENSE_KEY automatically. Never commit the key to git or share it publicly - it is unique to your purchase.
How the agent stays licensed
On startup the agent calls the validation endpoint with your key. If your subscription lapses or is cancelled, validation fails and the agent stops on its next check.
GET https://coredhristi.com/api/license/validate
Header: x-license-key: CD-XXXX...
Response: { "valid": true, "expiresAt": "...", "asset": { ... } }Custom projects: briefs, bids, and escrow
Need something built for you instead of an off-the-shelf agent? Post a Project Brief from Dashboard, Project Briefs. You can attach requirement documents (PDF, Word, Excel, images, or plain text; export Google Docs to .docx or .pdf first). Verified developers browse briefs and submit bids with a price and delivery time. You review the proposals, and CoreDhristi suggests matching developers based on their skills.
When you accept a bid, the project runs through four escrow milestones of 25% each. You fund a milestone, the developer delivers and marks it complete, and the money releases only when you approve. If something is wrong, open a dispute and the CoreDhristi team reviews both sides. You are taken to the escrow tracker automatically after accepting a bid; it also stays linked from the brief's detail page. The same service fee (4% in India, 6% internationally) applies when funding a milestone, shown as its own line before you pay.
CoreDhristi AI: the consultant chatbot
CoreDhristi AI (bottom-right on every page) works like a consultant, not a search box: tell it about your business and it reasons about your likely pain points before recommending an agent, automation, or MCP server - with an explanation of why it fits, not just a bare list. If you share your own website's URL, it can look at that one public page (only with your explicit click, never automatically) to skip questions the page already answers; what it infers is always shown back to you as inferred, not asserted as fact, and you can ask it to forget the page at any time.
If nothing on the marketplace fits what you described, it says so plainly and offers to pass the details - your business context and the specific gap - to the CoreDhristi team, so we can follow up or point you at a custom build. It never invents an agent that does not exist, and it never presents itself as compliance, legal, or financial advice.
For Creators: list and sell your agent
Listing is free, with a generous cap (100 listings today) and you keep a flat 80% of every sale - the platform fee is 20%, nothing else. The flow: sign up as a developer or seller, connect GitHub from the Creator Studio (this installs the CoreDhristi GitHub App with read-only access to only the repos you pick), create your listing, and submit it for review. Your repo URL is never shown to buyers, and buyers install through the CLI without ever seeing your GitHub.
Optional, never required: you can promote a listing for Rs 999 a month (US$20 for international creators). A promoted listing sorts above unpromoted ones, carries a visible “Promoted” label, and your bids on project briefs are shown first. It buys placement only - it does not skip any part of the security review, and it does not change your 80% share. An unpromoted listing stays free and fully visible. The same product, at the same price, also promotes your developer profile itself (Dashboard, Promote Profile) - it sorts you above unpromoted developers in the hire-a-developer directory and in CoreDhristi AI's own suggestions, and never changes what a company sees about your skills, rating, or KYC status.
Paid listings must be priced at least Rs 1,500 (about $18 for international creators) - one-time, monthly, or yearly, your choice. Free listings are welcome too. Once your listing passes review it goes live with a Verified badge, and listing your agent automatically gets you a free CoreDhristi Verified certificate the moment its 7-layer scan passes - no separate fee, no extra step. See Getting your agent certified below if you want a certificate without listing on the marketplace at all.
One rule to know before you list: an agent with active company subscribers cannot be pulled without 90 days notice. Removing a listing without notice freezes pending payouts and flags the account, so plan deprecations ahead.
The 7-layer review, explained
Every listing runs seven layers of checks before it can carry the Verified badge. They all run automatically in an isolated runner on GitHub's infrastructure (not on CoreDhristi's servers, and never on a buyer's machine):
1. Secret scanning (Betterleaks) catches committed API keys and credentials. 2. Static security analysis (Semgrep and CodeQL) checks the code against OWASP Top 10 patterns. 3. Dependency and supply-chain scanning (OSV-Scanner) checks every third-party library for known CVEs, across JavaScript, TypeScript, Python and more. 4. QA and functionality: the runner installs your agent the way a buyer would, runs its build, and executes your own test suite; an agent that does not install or build is rejected. 5. Automated attack-simulation (Promptfoo) probes the agent against dozens of known attack and vulnerability patterns. 6. Workflow and MCP verification (Agentic Radar, MCP Inspector) traces what an automation actually does and what tools an MCP server really exposes, each on the listing types it applies to. 7. Data-claim cross-check and SBOM (Presidio, Syft) checks personal-data handling against what you declared and publishes the full dependency set. The scan pipeline itself is fully automated end to end; an admin reviews the results before final approval. Layers 1 to 5 gate approval today; layers 6 and 7 run and are recorded on your listing and do not block it yet.
Getting your agent certified (with or without listing)
Listing your agent on the marketplace gets you the 7-layer scan (above) and a free CoreDhristi Verified certificate automatically the moment it passes - no extra fee, no separate step. If you do not want to list at all - you just want your own already-built agent, automation, or MCP server run through the same 7-layer scan and issued a certificate you can share - submit it from Dashboard, Creator, Certifications instead. That path is Rs 5,000 per scan for India-based submitters, US$120 internationally, charged only once the scan passes and you download the certificate (a failed scan is never charged). Certification is priced and scoped per agent version: any code update needs a fresh scan and a fresh certificate, and every certificate states plainly which version it was issued for. Certificates are publicly verifiable at a QR-coded link (coredhristi.com/verify/<id>) that always reflects the current, live status.
How your code is protected
Because your code runs on the buyer's own server, every install carries a fingerprint: a disclosed, per-license identifier embedded in the delivered code so a leaked copy traces back to the account that leaked it. JavaScript listings are obfuscated automatically at install time (TypeScript listings get the same protection whenever a build artifact exists to obfuscate instead of the raw source), and the Terms prohibit redistribution beyond the licensed deployment. None of this claims to make copying impossible - no marketplace has solved that completely - see coredhristi.com/trust for the honest, full explanation of what is and is not protected today.
Earnings, the 21-day hold, and monthly payouts
Companies are billed monthly per subscription. Each sale's 80% creator share first sits in a 21-day buyer-protection hold: it releases early if the company confirms satisfaction, or automatically after 21 days if no valid quality complaint was filed ("we did not use it much" is never a valid complaint - subscriptions are access-based). Cleared funds are then paid out automatically on the monthly payout run (the 1st of each month) once your balance reaches Rs 1,000. Configure your bank or UPI details in Dashboard, Earnings. Cross-currency sales convert at the official rate on settlement day.
Messages and platform rules
Once you have a project or hire relationship, chat with the other party in Dashboard, Messages. Keep the conversation on CoreDhristi: sharing phone numbers, emails, or external meeting links is detected automatically, warned on the first attempt, and blocked on repeat attempts. Messages are retained (encrypted) as dispute evidence, and CoreDhristi is not responsible for anything that happens off-platform after a warning.
Common problems and fixes
"Invalid license key"
The key was mistyped or copied with spaces. Copy it again from Dashboard, My Agents.
"License is inactive" or "expired"
Your subscription lapsed. Renew from Dashboard, Billing.
"Key does not match this asset"
That key belongs to a different agent. Each subscription has its own key - use the one issued for the agent you are installing.
My scan failed - what now?
Open your listing in Creator Studio to see which layer failed and why. Fix the finding (remove the committed secret, patch the dependency, make the build pass) and resubmit - there is no penalty for re-scanning.