# Immiscible > Immiscible checks what your AI agents ask to spend, share and do before they do it, asks a person when your rules say so, and keeps a signed record of every decision. ## Start here - [Immiscible documentation](https://immiscible.fly.dev/docs.md): See what your company spends on AI, what it could save, and which keys nobody is watching. Then put every agent's model requests, payments and tool calls behind rules a person wrote, with a record anyone can check. - [For finance teams](https://immiscible.fly.dev/docs/finance.md): Getting started without writing any code. See what the company spends on AI and what it could save, give each team a budget, and choose who approves when an agent wants to spend above your line. - [The console](https://immiscible.fly.dev/docs/console.md): A short tour of the console for whoever answers requests and watches the money. Where each thing lives, how to review a held request with its evidence beside it, and the keys that make a busy morning quick. - [Add the analyst to Claude](https://immiscible.fly.dev/docs/analyst.md): The AI spend analyst lives in Claude, Claude Code, Cursor and ChatGPT through Immiscible's MCP server. Ask it what you spent on AI, what is being wasted and which keys nobody is watching. When it wants to change something, a person approves first. - [Quickstart in five minutes](https://immiscible.fly.dev/docs/quickstart.md): One command creates an agent with a payment rule. Then watch Immiscible send one payment to a person, allow it once they approve, and refuse a lookalike supplier on its own. - [For AI agents](https://immiscible.fly.dev/docs/ai-agents.md): Everything an agent, or the person wiring one up, needs on one page. Ask before acting, follow the decision, retry safely, keep the receipt, and report what happened. Copy-paste setups for Claude Code, the OpenAI Agents SDK, MCP clients and x402. - [The Immiscible CLI](https://immiscible.fly.dev/docs/cli.md): One command governs the agent in your project. Sign in through the browser, create the agent and its rule, write .env, install the Claude Code hook and make a live test call. Works for people and for AI coding agents running non-interactively. - [What is Immiscible?](https://immiscible.fly.dev/docs/faq.md): Short, plain answers: what Immiscible is, how it differs from AI gateways, observability tools and card controls, what it costs, whether you can run it yourself, and what it does not do. - [How Immiscible compares](https://immiscible.fly.dev/docs/compare.md): Immiscible beside the kinds of tool it is most often mistaken for: AI gateways, LLM observability, corporate card controls, agent frameworks' built-in guardrails and wallet policy engines. By category, factually, including where each is the better fit. ## Spend - [Route model traffic through the gateway](https://immiscible.fly.dev/docs/guides/gateway.md): Change one base URL and every model request is metered, routed under your policy, checked against budgets before the call, and recorded. Your agents' context is observed, so the gate judges what actually entered it. - [Route through OpenRouter](https://immiscible.fly.dev/docs/guides/openrouter.md): Keep OpenRouter and put governance above it. Requests go out with your attribution and routing preferences, allowlists apply to the vendor and model behind each route, and every call is billed on the cost OpenRouter itself reports. - [Find shadow agents with discovery](https://immiscible.fly.dev/docs/guides/discovery.md): Connect OpenAI, Anthropic and OpenRouter with an admin credential and every key, project and workspace your people run outside Immiscible shows up, with its owner and its spend. Bring each one under control in one click, or propose revoking it. - [The agent inventory](https://immiscible.fly.dev/docs/guides/agent-inventory.md): Find agents in Microsoft Entra and Agent 365, Google Workspace, n8n and Zapier, read only, beside the keys discovery finds at OpenAI, Anthropic and OpenRouter. One row per agent, with owners, verb-level permissions, consent type and lifecycle, the findings that matter, and one click to put each under rules. - [AI spend where finance already looks](https://immiscible.fly.dev/docs/guides/finance-dashboards.md): A Google Sheet of AI spend by team, provider and agent, and every decision, refreshed daily; the same views as CSV for Excel, Looker Studio, Metabase or a warehouse; and a read-only summary link for a board. - [Export AI spend to Xero](https://immiscible.fly.dev/docs/guides/xero.md): Connect Xero by signing in, choose the accounts once, then close each month in one click as a draft manual journal or a draft bill, a line per team or cost centre. - [Export AI spend to QuickBooks Online](https://immiscible.fly.dev/docs/guides/quickbooks.md): Connect QuickBooks Online by signing in with Intuit, choose the accounts once, then close each month in one click as a journal entry or a bill. - [NetSuite](https://immiscible.fly.dev/docs/guides/netsuite.md): NetSuite export is set up on request. Today the chargeback downloads as a NetSuite journal import CSV. ## Approvals - [Govern Claude Code and Cursor](https://immiscible.fly.dev/docs/guides/mcp-proxy.md): Put every tool call a coding agent makes behind the gate. The MCP proxy holds the tool's credential and the agent connects only to Immiscible, so there is no path to the tool that skips the decision. - [Approvals in Slack and Teams](https://immiscible.fly.dev/docs/guides/approvals-in-chat.md): Approval requests reach people where they already are, with Approve and Deny in the message. A decision in chat is the console's decision, with every rule the console applies. - [Personal workspaces](https://immiscible.fly.dev/docs/guides/personal-workspaces.md): One person governing their own agents: a monthly allowance, a never-pay list, a card per agent, approvals on your phone and one switch that stops everything. The same identifiers and evidence a company gets, with defaults for a person. - [Agents without an API, such as Instinct](https://immiscible.fly.dev/docs/guides/agents-without-an-api.md): Some agents publish no API, no MCP support and no admin console you can connect. Instinct is one. Here is what Immiscible can and cannot govern for them, said plainly, and how to set it up. - [Ask Immiscible before acting, from any agent builder](https://immiscible.fly.dev/docs/guides/openapi-actions.md): The decision API is published as OpenAPI 3.1 at /openapi.json, with a 3.0 copy and a Power Platform connector. Import it as an action, or connect a builder to the MCP server, so the agents people build without code ask before they pay, share data or act. - [The kill switch](https://immiscible.fly.dev/docs/guides/kill-switch.md): Stop one agent or a whole fleet at once, from the console, a phone, Slack, a SOAR playbook or your identity provider. A stopped agent is refused on every path Immiscible enforces, including its model calls. - [Govern Copilot Studio agents](https://immiscible.fly.dev/docs/guides/copilot-studio.md): Connect a Microsoft Copilot Studio agent to the Immiscible MCP server, or import our Power Platform custom connector, so it asks before it pays, shares data or acts. - [Holds and drills](https://immiscible.fly.dev/docs/guides/holds-and-drills.md): A hold says who may start a frozen agent again. A drill proves the kill switch works, end to end, and leaves a signed report. - [Traces and reviews](https://immiscible.fly.dev/docs/guides/traces-and-reviews.md): Follow one piece of work end to end through every record it touched, have people look at what agents did after they did it, and take back access nobody vouches for. ## Concepts - [How it fits together](https://immiscible.fly.dev/docs/concepts.md): What Immiscible does, the six pieces it is made of, the four ways an agent reaches the gate, and the conventions these docs use. - [Decisions](https://immiscible.fly.dev/docs/concepts/decisions.md): Every action request gets one of three answers, with reasons a person can read and the signals that produced them. This page is the whole of how an answer is reached. - [Mandates](https://immiscible.fly.dev/docs/concepts/mandates.md): A mandate is a standing authority granted to one agent. It is written for a person to read and enforced by a machine, and it is signed, so nobody can edit it in the database without the signature failing. - [Autonomy tiers](https://immiscible.fly.dev/docs/concepts/autonomy-tiers.md): How much an agent may do without a person is earned on evidence, one rung at a time, with sign-off from the people who carry the risk. An agent nobody has graded is an intern. - [Receipts](https://immiscible.fly.dev/docs/concepts/receipts.md): Every allowed action carries a short signed token that says which agent was allowed to do what, under which mandate, and whether a person approved it. Anyone can check it, online or offline. - [Evidence](https://immiscible.fly.dev/docs/concepts/evidence.md): Every decision, approval, freeze, promotion and change of access is a record in a hash-chained ledger whose head is signed at intervals. A rewrite shows, and you can check it without trusting us. ## Answers - [Answers](https://immiscible.fly.dev/docs/answers.md): Short, direct answers to the questions people ask about controlling what AI agents spend, share and do, each with the commands or code to do it and what it cannot do. - [How do I stop an AI agent from spending money without approval?](https://immiscible.fly.dev/docs/answers/stop-an-agent-spending.md): Put a decision in front of every payment the agent makes, with an amount above which a person must approve. With Immiscible that is one rule ("ask me above £500") and a gate the payment has to pass. - [How do I add Immiscible's MCP server to Claude Code, Cursor or VS Code?](https://immiscible.fly.dev/docs/answers/add-the-mcp-server.md): One command in Claude Code, one JSON entry in Cursor, VS Code, Windsurf, Codex or Gemini CLI, or a custom connector in Claude and ChatGPT. The server is at /mcp and takes an agent key or OAuth sign-in. - [How do I block dangerous commands in Claude Code?](https://immiscible.fly.dev/docs/answers/claude-code-block-commands.md): Use a PreToolUse hook, which Claude Code runs before every tool call whatever the model decides. Immiscible's hook sends each Bash command, file edit, web fetch and MCP call to a rule a person wrote and refuses, asks or allows; it fails closed. - [How do I make Cursor's agent ask before risky tool calls?](https://immiscible.fly.dev/docs/answers/cursor-agent-safety.md): Put the MCP tools Cursor's agent uses behind Immiscible's MCP proxy, and add Immiscible's MCP server so it can ask before paying or sharing data. Keep Cursor's own settings for its terminal commands; Immiscible's hook is for Claude Code. - [How do I make an AI agent ask a person before it acts?](https://immiscible.fly.dev/docs/answers/human-approval-for-agents.md): Route each consequential action through a decision that can answer "a person decides". Immiscible holds the request, asks the named person in the console, by email, in Slack or in Teams, and tells the agent once they have decided. - [How do I add approval to tool calls in the OpenAI Agents SDK, LangGraph or the Vercel AI SDK?](https://immiscible.fly.dev/docs/answers/framework-tool-approvals.md): Wrap the framework's tools with Immiscible's guard. Each tool keeps its name and schema, asks before it runs, waits for a person when the rule says so, and returns a refusal to the model as the tool's result. - [How do I allow or deny MCP tool calls by policy?](https://immiscible.fly.dev/docs/answers/mcp-tool-permissions.md): Put the MCP server behind a proxy that holds its credential and decides each tools/call against a rule. Immiscible's MCP proxy lists only the tools a rule covers, refuses or asks about the rest, and records every call as a digest. - [How do I stop an AI agent sending data where it should not?](https://immiscible.fly.dev/docs/answers/agent-data-exfiltration.md): Decide every outbound action by where it goes, and keep personal data out of the agent's hands until a release is allowed. Immiscible refuses destinations a rule does not name, releases personal data from a vault only to allowed recipients, and judges actions on what the agent has read. - [How do I control LLM costs per team?](https://immiscible.fly.dev/docs/answers/llm-costs-per-team.md): Send model traffic through a gateway that checks a budget before each call. Immiscible's gateway takes OpenAI-shaped and Anthropic-shaped requests on your own provider keys, and holds monthly budgets per team, person or workspace that nudge, downgrade, ask the owner and then stop. - [How do I control what an AI agent pays with x402 or a crypto wallet?](https://immiscible.fly.dev/docs/answers/x402-and-wallet-payments.md): Decide each payment before the wallet signs. Immiscible's SDK reads the HTTP 402, asks with the payment requirements, and calls your x402 signer only on allow; for wallets it decides first and your wallet signs after. It never holds keys. - [How do I stop all my AI agents at once?](https://immiscible.fly.dev/docs/answers/kill-switch-for-ai-agents.md): Freeze them where every request they make is decided. A stopped agent in Immiscible is refused on every path it enforces, its actions, model calls, proxied tool calls and card authorisations, and only a person can start it again. - [What logging do AI agents need for the EU AI Act?](https://immiscible.fly.dev/docs/answers/eu-ai-act-logging.md): For a high-risk AI system, Article 12 asks for automatic recording of events over its lifetime, and Articles 19 and 26(6) ask providers and deployers to keep those logs for at least six months. Immiscible records every agent decision automatically in a signed, hash-chained ledger you can export and verify; it supports a compliance file, it does not make anyone compliant. - [What kinds of tool control what AI agents spend and do?](https://immiscible.fly.dev/docs/answers/tools-for-controlling-ai-agents.md): Seven kinds, each good at something different: the controls built into the agent, LLM gateways, MCP gateways and proxies, guardrail libraries, card and payment controls, wallet policy engines, and an independent control layer such as Immiscible. Which to use depends on what the agent can do and who needs to see the record. ## Identity - [Identity and access profiles](https://immiscible.fly.dev/docs/guides/identity-and-access.md): Every agent, person and application has an identifier no AI can change. Each agent has a signed, versioned access profile, and never exceeds the entitlements of the person it acts for. - [Security administration](https://immiscible.fly.dev/docs/guides/security-admin.md): The controls owners and admins set for a whole workspace (single sign-on, two-factor, session limits, IP allowlists, sign-in methods, domain capture, retention) and the records an administrator or auditor reads (sessions, the audit log, the roles matrix, trust data). - [Shared Signals from Okta or Entra](https://immiscible.fly.dev/docs/guides/shared-signals.md): When your identity provider disables an account, revokes a session or flags a compromised credential, the agents acting for that person stop within seconds, under a security hold. ## Agent payments - [The card rail with Stripe Issuing](https://immiscible.fly.dev/docs/guides/card-rail.md): Bind a virtual card to an agent and the card issuer asks Immiscible in real time before money moves. No receipt, no payment. Every authorisation, approved or declined, is evidence. - [Crypto payments](https://immiscible.fly.dev/docs/guides/crypto-payments.md): Govern agents that pay in USDC, USDT, EURC, ETH, BTC or SOL. Limits stay in pounds; each payment is priced at the moment it is decided, and the wallet signs only after an allow. - [Reconcile Ramp charges against receipts](https://immiscible.fly.dev/docs/guides/ramp.md): Connect Ramp, map each agent's card to the agent, and every charge is reconciled against the receipt that allowed it. Ramp saw the charge; Immiscible says why it happened, and can write that into the Ramp memo. - [Rates, and the "never guessed" rule](https://immiscible.fly.dev/docs/guides/crypto-rates.md): How a crypto payment is priced at the moment it is decided, where the rate comes from, how long it is reused, and what happens when there is no rate. - [x402 payments](https://immiscible.fly.dev/docs/guides/x402.md): Pay x402 resources only when Immiscible allows it. The SDK reads the 402, asks with the payment requirements, and calls your x402 signer only on allow. - [Fireblocks](https://immiscible.fly.dev/docs/guides/fireblocks.md): The Fireblocks API Co-Signer calls Immiscible before it signs each transfer, and signs only when an unused receipt covers it. - [Coinbase CDP wallets and AgentKit](https://immiscible.fly.dev/docs/guides/coinbase-cdp.md): Coinbase's server wallets have a policy engine but no outside approval call, so the agent asks Immiscible before it sends. - [Turnkey](https://immiscible.fly.dev/docs/guides/turnkey.md): Turnkey's policies and approvals stay inside Turnkey and its webhooks are notifications, so the agent asks Immiscible before it requests a signature. - [Privy server wallets](https://immiscible.fly.dev/docs/guides/privy.md): Privy's policies stay inside Privy and its transaction webhooks fire after broadcast, so the agent asks Immiscible before it sends. - [Circle wallets and USDC](https://immiscible.fly.dev/docs/guides/circle.md): Circle's screening runs inside Circle and its webhooks are notifications, so the agent asks Immiscible before it transfers. ## Deploy - [Deploy and backups](https://immiscible.fly.dev/docs/guides/deploy-and-backups.md): One Node 22 process with no runtime dependencies and one SQLite file. Run it in your own VPC, keep the master key safe, back up the evidence, and know what failover does and does not exist. ## SDKs - [SDKs](https://immiscible.fly.dev/docs/sdks.md): Zero-dependency clients for JavaScript and Python. One call asks the gate, waits for a person if it must, runs your code only on allow, and settles the outcome. - [Immiscible SDKs](https://immiscible.fly.dev/docs/sdks/overview.md) - [Claude Code and the Claude Agent SDK](https://immiscible.fly.dev/docs/sdks/integrations/claude-code.md) - [LangChain and LangGraph](https://immiscible.fly.dev/docs/sdks/integrations/langchain.md) - [MCP clients: Claude Desktop, Cursor, VS Code, Claude Code](https://immiscible.fly.dev/docs/sdks/integrations/mcp.md) - [OpenAI Agents SDK](https://immiscible.fly.dev/docs/sdks/integrations/openai-agents.md) - [Vercel AI SDK](https://immiscible.fly.dev/docs/sdks/integrations/vercel-ai.md) - [Quickstart: from key to first governed tool call](https://immiscible.fly.dev/docs/sdks/quickstart.md) ## Security - [Evidence specification](https://immiscible.fly.dev/docs/security/evidence-spec.md): An open description of the evidence Immiscible keeps (records, checkpoints and bundles) so anyone can check it without us. - [Verifying offline](https://immiscible.fly.dev/docs/security/verifying-offline.md): Check receipts, evidence bundles, checkpoints and signed reports with nothing but the public keys you kept, without calling Immiscible and without trusting us. - [Threat model](https://immiscible.fly.dev/docs/security/threat-model.md): What Immiscible defends against, the rules it enforces in code, and the limits we name before someone else does. - [Security reviews](https://immiscible.fly.dev/docs/security/security-reviews.md): Everything a security, legal or IT review needs from Immiscible, in one download, with the gaps named. ## API reference - [API reference](https://immiscible.fly.dev/docs/api.md): Every route the Immiscible server answers, generated from the router itself at start-up, so the reference cannot fall behind the code. Each endpoint has its authentication, parameters and curl, Node and Python examples. - [Authentication](https://immiscible.fly.dev/docs/api/authentication.md): Five kinds of caller, never mixed. Each route accepts exactly one, and a credential presented on a route that does not take it is not even read. - [Errors and headers](https://immiscible.fly.dev/docs/api/errors.md): Errors come back in the shape your client already expects, with a stable type and a message in plain English. Headers that steer the gateway, and the ones it sends back. ## Changelog - [Changelog](https://immiscible.fly.dev/docs/changelog.md) ## Machine-readable - [OpenAPI 3.1 for the decision API](https://immiscible.fly.dev/openapi.json): authorise, poll, explain, settle and verify actions; the model gateway; machine admin; the CLI, MCP, SCIM and well-known routes, each typed from its documented example. The console's own routes are not in it - [All endpoints](https://immiscible.fly.dev/docs/api/endpoints.md): Every route the server answers, 555 in all, generated from the router at start-up. - [MCP server](https://immiscible.fly.dev/mcp): Streamable HTTP, JSON-RPC 2.0; tools authorize_action, request_payment, request_personal_data, check_action_status, explain_decision, settle_action, spend_summary, find_waste, unwatched_keys, set_budget, revoke_key; authenticate with an agent key or OAuth - [MCP server card](https://immiscible.fly.dev/mcp/server-card): the server's name, transport and tools, listed in https://immiscible.fly.dev/.well-known/ai-catalog.json - [Receipt signing keys](https://immiscible.fly.dev/.well-known/immiscible-keys.json): the Ed25519 JWKS for verifying receipts offline - [The core in one file](https://immiscible.fly.dev/llms-full.txt): getting started, the concepts, the answers and the decision API, as Markdown - [Spend, in one file](https://immiscible.fly.dev/llms-full/spend.txt): 8 pages: Route model traffic through the gateway, Route through OpenRouter, Find shadow agents with discovery, The agent inventory, and more - [Approvals, in one file](https://immiscible.fly.dev/llms-full/approvals.txt): 9 pages: Govern Claude Code and Cursor, Approvals in Slack and Teams, Personal workspaces, Agents without an API, such as Instinct, and more - [Identity, in one file](https://immiscible.fly.dev/llms-full/identity.txt): 3 pages: Identity and access profiles, Security administration, Shared Signals from Okta or Entra - [Integrations, in one file](https://immiscible.fly.dev/llms-full/integrations.txt): 19 pages: The Claude Code fleet pack, Setting up Slack, Setting up Microsoft Teams, Hooks for Codex, Cursor, Windsurf and Gemini CLI, and more - [Agent payments, in one file](https://immiscible.fly.dev/llms-full/agent-payments.txt): 10 pages: The card rail with Stripe Issuing, Crypto payments, Reconcile Ramp charges against receipts, Rates, and the "never guessed" rule, and more - [Deploy, in one file](https://immiscible.fly.dev/llms-full/deploy.txt): 1 page: Deploy and backups - [SDKs, in one file](https://immiscible.fly.dev/llms-full/sdks.txt): 8 pages: SDKs, Immiscible SDKs, Claude Code and the Claude Agent SDK, LangChain and LangGraph, and more - [Security, in one file](https://immiscible.fly.dev/llms-full/security.txt): 4 pages: Evidence specification, Verifying offline, Threat model, Security reviews - [Changelog, in one file](https://immiscible.fly.dev/llms-full/changelog.txt): 1 page: Changelog - [API reference, in one file](https://immiscible.fly.dev/llms-full/api.txt): every route (555), with what each does and how it authenticates ## Optional - [The Claude Code fleet pack](https://immiscible.fly.dev/docs/guides/claude-code-fleet.md): Govern every Claude Code session on a machine, or on every machine you manage, with one command. A managed hook people cannot switch off, a baseline rule that refuses force pushes to main and asks before terraform apply in production, and an http hook endpoint. - [Setting up Slack](https://immiscible.fly.dev/docs/guides/slack.md) - [Setting up Microsoft Teams](https://immiscible.fly.dev/docs/guides/teams.md) - [Hooks for Codex, Cursor, Windsurf and Gemini CLI](https://immiscible.fly.dev/docs/guides/coding-agent-hooks.md): One command puts a fail-closed Immiscible hook in front of Codex, Cursor, Windsurf or Gemini CLI, for one person or for every person on a machine through the agent's managed settings. Shell commands, MCP tool calls and file writes are decided by the same rules as Claude Code's. - [Setting up sign-in](https://immiscible.fly.dev/docs/guides/sign-in.md) - [Workspace single sign-on](https://immiscible.fly.dev/docs/guides/workspace-sso.md): Sign a workspace's people in through Okta, Microsoft Entra ID or Google Workspace with OpenID Connect, prove your email domains, and require it. - [Connect your customers' workspaces, for agent platforms](https://immiscible.fly.dev/docs/guides/agent-platforms.md): For companies that build agent products. Register your product once, let each customer connect their Immiscible workspace with OAuth, then add an agent for them and ask before it acts. Their people approve in Slack or Teams, and every decision comes back signed. - [Ask Immiscible from an n8n workflow](https://immiscible.fly.dev/docs/guides/n8n.md): Import a ready workflow that asks Immiscible before acting, waits for a person with n8n's Wait node when it has to, then acts and records what happened. - [Ask Immiscible from a Zap](https://immiscible.fly.dev/docs/guides/zapier.md): A recipe for Zapier. Webhooks by Zapier asks before the action; when a person has to decide, a second Zap started by a catch hook carries on once they have. - [Ask Immiscible from a Make scenario](https://immiscible.fly.dev/docs/guides/make.md): A recipe for Make. The HTTP module asks before the action; when a person has to decide, a second scenario started by a custom webhook carries on once they have. - [EU AI Act evidence for deployers](https://immiscible.fly.dev/docs/guides/eu-ai-act-deployers.md): A clause-level map of the deployer obligations in Articles 12, 14, 26 and 27 to the Immiscible records that evidence them, what Immiscible does not cover, and the evidence pack an auditor can take away. - [SIEM export](https://immiscible.fly.dev/docs/guides/siem-export.md): Send the evidence ledger to Splunk, Sentinel, Chronicle or any SIEM as OCSF 1.3, or to a tracing backend as OpenTelemetry. Pull it on a schedule, or have it pushed by signed webhook. - [Incidents in PagerDuty](https://immiscible.fly.dev/docs/guides/pagerduty.md): Connect PagerDuty and the kill switch, over-settlements, held high-value payments and spent budgets open one incident each, resolved when they end. - [Alerts in Opsgenie](https://immiscible.fly.dev/docs/guides/opsgenie.md): The same incidents as PagerDuty, as Opsgenie alerts closed when they end, with one API key. - [Ledger records in Datadog](https://immiscible.fly.dev/docs/guides/datadog.md): Every ledger record as an OCSF log at your Datadog site, with one API key checked live. - [Ledger records in Splunk](https://immiscible.fly.dev/docs/guides/splunk.md): Every ledger record as an OCSF event to your HTTP Event Collector, with the URL and token proven by a test event. - [Signed webhooks for everything else](https://immiscible.fly.dev/docs/guides/signed-webhooks.md): Chosen ledger events to your own endpoint, signed with HMAC-SHA256 over a timestamp, with a replay window and a delivery id. - [Deploying Immiscible](https://immiscible.fly.dev/docs/guides/deploy.md) - [PostgreSQL](https://immiscible.fly.dev/docs/guides/postgres.md)