The right way
AI agents write code.
Register a model, get a secure API. Permissions, validation, multi-tenancy, and audit trails — all built in. AI agents ship better code when the framework, not the model, owns the conventions.
Describe what you need.
AI writes the Blueprint.
Claude and Cursor read the Rhino conventions and emit a YAML blueprint. You review it like a diff. The framework — not the model — turns it into production code.
- Declarative. No more guessing at controllers.
- Reviewable. A 30-line YAML beats a 300-line PR.
- Deterministic. Same YAML → same code, every time.
Contract model with title, total_value, and status. Admins can create all fields but only update title + status. Viewers can see id, title, status only.model: Contract columns: - title: string # required - total_value: decimal - status: enum(draft, signed, void) permissions: admin: create: [title, total_value, status] update: [title, status] show: * viewer: show: [id, title, status]
From YAML to production code.
Fully deterministic.
Define the permission matrix once. Generate policies, migrations, tests, and seeders — no AI in the loop.
# Source of truth model: Contract traits: [uuid, soft_deletes, org] columns: - title: string(140) - total_value: decimal(12,2) - status: enum(draft,signed,void) permissions: admin: create: * update: [title, status] show: * viewer: show: [id, title, status] query: filters: [status, owner_id] sorts: [created_at, total_value] search: [title]
class ContractPolicy extends ResourcePolicy { public function permittedAttributesForShow(User $user): array { return match ($user->roleFor($this->org)) { 'admin' => ['*'], 'viewer' => ['id', 'title', 'status'], default => [], }; } public function permittedAttributesForUpdate(User $user): array { return match ($user->roleFor($this->org)) { 'admin' => ['title', 'status'], default => [], }; } }
Everything you need,
out of the box.
AI-Native Architecture
Declarative, config-driven models that AI agents can read, scaffold, and extend. Built to be prompted, not hand-coded.
Blueprint Generator
Define your permission matrix in YAML, generate fully working policies, tests, and seeders — zero AI tokens, fully deterministic.
Automatic CRUD
Register a model, get full REST endpoints instantly. Index, show, store, update, destroy — plus soft-delete, restore, force-delete.
Auth, Policies & RBAC
Token-based auth, role-based access control, and a ResourcePolicy base with attribute-level permissions. Per org, per role.
Advanced Querying
Filtering, sorting, full-text search, pagination, sparse fieldsets, and eager-loading — all via query string. No controller work.
Multi-Tenancy
Organization-based data isolation with BelongsToOrganization. Cross-tenant FKs are auto-scoped. Subdomain or route-prefix.
Register a model.
Get a full API. Use a hook.
class Post extends Model { use HasRhino, BelongsToOrganization, SoftDeletes; protected $fillable = ['title', 'body', 'published_at']; public $allowedFilters = ['author_id', 'published']; public $allowedSorts = ['-published_at', 'title']; public $allowedIncludes = ['author', 'comments']; public function validationRules(): array { return ['title' => 'required|max:120', 'body' => 'required']; } }
return [ 'resources' => [ App\\Models\\Post::class => [ 'slug' => 'posts', 'policy' => App\\Policies\\PostPolicy::class, 'middleware' => ['auth:sanctum'], ], ], ];