You open Claude Code, type /model, and scroll. No Jev. You try Cursor's model picker. No Jev there either. Then the search results offer a dozen answers at once — install an MCP server, add a plugin, "connect it via Vercel" — and none of them says what you will actually get at the end.
Here is the part most guides bury: Jev cannot be the model behind Claude Code, Cursor or Codex. TypeSafe's own documentation says so in its first paragraph on coding agents. A coding agent needs a model that writes text, calls tools and edits files; Jev returns typed answers with probabilities and never writes a word. (If that distinction is new, our explainer on what Jev is covers it in five minutes.)
What does work is more useful than a model swap. Your coding agent can learn the Jev API and write correct integrations for you. Jev can clear the routine permission prompts that interrupt every session. And one router on OpenRouter lets Jev decide which model answers each request.
We checked every command and config file below against the current official documentation from TypeSafe, Anthropic, Cursor, OpenRouter and Vercel on September 30, 2026. These are the vendors' documented setups, not ones we have run end to end ourselves, and we say so explicitly where a step goes beyond what the documentation shows. By the end you will know which of the four setups fits what you were trying to do, and exactly how to install it.
Last updated September 30, 2026. Every tool in this guide ships updates weekly; the linked documentation wins if anything here disagrees with it.
Why Jev Can't Be the Model Behind Claude Code or Cursor
TypeSafe's page on Jev with coding agents is blunt: Jev is not a drop-in replacement for the LLM behind Claude Code, Cursor, Copilot or similar tools, and there is no model setting that turns a coding agent into a Jev-powered one.
The reason is mechanical. A coding agent streams text, emits tool calls and writes files from natural-language instructions. Jev takes a state and a set of declared choice, score and noul questions and returns one typed answer per question. There is no completion endpoint to point an editor at, because there is no completion.
So the useful question is not "how do I select Jev" but "what was I hoping Jev would do?"
| What you wanted | What actually works | Setup |
|---|---|---|
| Have Claude Code or Cursor write code that uses Jev | TypeSafe's official agent skill | 2 commands |
| Use Jev in the app or agent you are building | Call the Jev API from that code | An API key |
| Fewer "allow this command?" interruptions | A permission hook that asks Jev first | 1 script + 1 config file |
| Cheaper or faster coding sessions | Jev Router on OpenRouter picks the model per request | Environment variables |
| Jev as the chat or coding model | Not possible | — |
The rest of this guide takes those four in order, then answers the three questions that come up most: the terminal, "via Vercel", and Claude Cowork.
Step 1: Install the TypeSafe Skill in Claude Code, Cursor or Codex
This is the setup TypeSafe recommends first, and the one most people actually need. The TypeSafe agent skill gives your coding agent the current API contract, the three question types and TypeSafe's design patterns, so the code it writes for you uses real request fields instead of guessed ones.
In Claude Code, run these two commands in your terminal:
claude plugin marketplace add typesafe-ai/skills
claude plugin install typesafe@typesafe-ai
Invoke it directly with /typesafe:typesafe-ai, or just say "use the TypeSafe skill" in a prompt. To update later, run claude plugin marketplace update typesafe-ai and claude plugin update typesafe@typesafe-ai, then restart or run /reload-plugins.
In Cursor, Codex and other agents, use the skills installer:
npx skills add typesafe-ai/skills --skill typesafe-ai
Choose your agent when prompted. It installs into the current project by default; add -g to install it globally. Cursor loads skills from .agents/skills/ and .cursor/skills/, and for compatibility also from .claude/skills/ and .codex/skills/ — so a project that already carries the skill for Claude Code works in Cursor too. In Cursor's Agent chat, type / and pick the skill to attach it to a message.
Then give the agent a real task rather than a vague one. For example:
Use the TypeSafe skill. Add a function that routes each incoming support
ticket to billing, technical or sales, and sends anything below 0.7
confidence to a human queue. Put the questions and thresholds in one file.
Which API key? The skill writes code for TypeSafe's own API, which reads TYPESAFE_API_KEY. If you use Jev through jev-ai.org instead, tell the agent the endpoint is https://jev-ai.org/api/v1/systemone/ with a bearer key. The request body is the same state and questions; the one difference in the response is billing — jev-ai.org reports charged_tokens, charged_credits and wallet in usage instead of a cost field. Our API docs have the full contract.
Rule of thumb from TypeSafe's own guidance: agents are not good at writing Jev questions. Keep every question and threshold in one file and review them yourself — that file is the part of the code that decides behaviour.
Step 2: Call Jev From the Code You Build
Once the skill is in place, the Jev part of your project is an ordinary HTTP call. The one the agent should produce looks like this — the exact shape from our docs:
curl https://jev-ai.org/api/v1/systemone/ \
-H "Authorization: Bearer $JEV_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"model": "jev-1.13",
"state": "Order #8814 arrived with a cracked screen. Third time this quarter.",
"questions": {
"refund_requested": {
"type": "noul",
"instructions": "Is the customer asking for a refund?"
}
}
}'
Run that from the same terminal your agent uses before you let it write anything bigger. If you get back an answers object with a probability, the key, the endpoint and the question shape are all correct, and every bug after that is in your own code. You can create a key and see pricing on the Jev AI API page.
How to Use Jev AI for Coding in the Terminal (Claude Code, Codex)
Jev will not write code in your terminal, and there is no local copy of it to run on your machine — TypeSafe has not released weights, which we cover in our Jev AI download guide. What the terminal workflow looks like in practice:
- Your terminal agent — Claude Code or Codex — writes and edits the code, with the TypeSafe skill installed.
- You or the agent test Jev calls with
curlor a short script, as in step 2. - For fully offline development, Ollama 0.35 serves open "Jev-style" decision models through the same
/v1/systemonerequest shape, so you can build against a local model and switch to hosted Jev by changing the base URL. Treat local answers as a stand-in: they are a different model.
Codex also supports the permission-hook pattern below, which is where Jev makes a terminal session itself faster.
Step 3: Let Jev Approve Routine Permission Prompts
Every coding agent that asks before running shell commands produces the same problem: dozens of prompts per session for git status, ls and test runs, or no prompts at all. OpenRouter published a recipe that keeps the prompt and lets Jev clear the obvious cases: auto-approving coding agent permission prompts with Jev, with hook variants for Claude Code, Codex CLI, Cursor and OpenCode.
The design has three layers, in this order:
- A static risk list in code catches recursive deletes, force pushes, publishing and deploying, privilege escalation and credential files. A match goes straight to your normal prompt; Jev is never asked.
- Two
noulquestions to Jev — is this command reversible and confined to the project, and does it serve the current task? - A threshold of 0.9. Only when every question clears it does the hook approve. Anything else — a low score, a timeout, a malformed response — leaves the prompt exactly as it was.
OpenRouter published captured runs against typesafe/jev-1.13 with a shared task of fixing one failing test:
| Command | Reversible | Serves the task | Result |
|---|---|---|---|
bun test src/utils/date.test.ts | 0.93 | 0.95 | Approved |
bun add left-pad | 0.45 | 0.09 | Prompts you |
npx wrangler deploy | 0.04 | 0.07 | Prompts you (also caught by the risk list) |
Each check with a 400-token state cost about $0.0000168 in those runs.
Register the hook in Claude Code
Claude Code runs PermissionRequest hooks only when it is about to ask you, so routine commands already on an allow rule never reach Jev. Save OpenRouter's script (it runs with Bun) and register it in .claude/settings.json in your project:
{
"hooks": {
"PermissionRequest": [
{
"matcher": "Bash",
"hooks": [
{
"type": "command",
"command": "bun ./path/to/jev-permission-hook.ts",
"timeout": 15
}
]
}
]
}
}
Two safety properties come from Claude Code itself, per its hooks reference: a hook's allow cannot override a matching deny rule in your settings, and in sessions that cannot show a prompt, a request with no hook decision is denied.
Register the hook in Cursor
Cursor's beforeShellExecution hook runs before every shell command, and its default on a crashed or timed-out hook is to let the command run. For an approval gate you want the opposite, so set failClosed in .cursor/hooks.json:
{
"version": 1,
"hooks": {
"beforeShellExecution": [
{
"command": "bun ./path/to/jev-permission-hook.ts",
"timeout": 15,
"failClosed": true
}
]
}
}
The Cursor version of the script must always answer, with allow or ask, and Cursor sends no task text — so only the reversibility question is asked and the static list carries more weight.
Pointing the hook at jev-ai.org
OpenRouter's script calls its Decisions endpoint with an OpenRouter key. To use a jev-ai.org key instead, only the request function changes; the risk list, questions and entry points stay as published. This adaptation is ours and we have not run it end to end in Claude Code or Cursor, so pipe a sample hook input into the script before relying on it:
const APPROVE_AT = 0.9;
type State = { commands: string[]; project: string; task?: string };
async function jevApproves(state: State): Promise<boolean | undefined> {
const questions: Record<string, { type: 'noul'; instructions: string }> = {
reversible: {
type: 'noul',
instructions:
'Every command in `commands` only reads or changes files inside `project` and can be undone with git or by rerunning it. It does not push, publish, deploy, delete files outside the project, change system settings, or send data to a network service.',
},
};
if (state.task) {
questions.serves_task = {
type: 'noul',
instructions: 'Running `commands` is a reasonable next step toward `task`.',
};
}
const res = await fetch('https://jev-ai.org/api/v1/systemone/', {
method: 'POST',
headers: {
Authorization: `Bearer ${process.env.JEV_API_KEY}`,
'Content-Type': 'application/json',
},
body: JSON.stringify({ model: 'jev-1.13', state, questions }),
signal: AbortSignal.timeout(8_000),
}).catch(() => undefined);
if (!res || !res.ok) return undefined; // leave the prompt alone
const body = await res.json().catch(() => undefined);
const scores = Object.keys(questions).map((key) => body?.answers?.[key]?.noul);
if (!scores.every((p) => typeof p === 'number' && p >= 0 && p <= 1)) return undefined;
return scores.every((p) => p >= APPROVE_AT);
}
Expert warning: Jev judges only the text of the command. A cat of a secret file with an innocent name looks routine. The static list — not the threshold — is your security boundary, so add your own production CLIs and remotes to it before you trust the hook.
Step 4: Let Jev Pick the Model With Jev Router
This is the only official way for Jev to influence which model answers inside your coding session. OpenRouter's Jev Router, model id typesafe/jev-router, has Jev read each request, judge the task type and difficulty, and send it to the cheapest model in a curated pool that clears the bar. OpenRouter documents that it works with the Chat Completions, Responses and Messages APIs, streaming or not.
Claude Code speaks the Messages API and can be pointed at OpenRouter with ANTHROPIC_BASE_URL=https://openrouter.ai/api, an OpenRouter key in ANTHROPIC_AUTH_TOKEN and an explicitly empty ANTHROPIC_API_KEY; its model slots can then be set with variables such as ANTHROPIC_DEFAULT_SONNET_MODEL. Cursor can reach OpenRouter through its OpenAI base-URL override at https://openrouter.ai/api/v1/cursor, where you add model ids by hand.
Putting typesafe/jev-router into one of those slots follows from the documentation, but we have not run it end to end, and OpenRouter itself warns that Claude Code is optimised for Anthropic models and may not work correctly with others. Try it on a throwaway project first, and check the model field of responses to see what Jev actually chose. Our Jev on OpenRouter guide covers the router's pool and restrictions in detail.
How Do I Connect Claude Code to Jev AI via Vercel?
This question mixes two separate connections that happen to share one Vercel AI Gateway key.
Connection 1 — Claude Code's own model traffic through AI Gateway. Vercel's setup command writes the gateway URL into Claude Code's settings for you:
npx vercel ai-gateway setup --agent claude-code
According to Vercel's Claude Code guide, this sets ANTHROPIC_BASE_URL to https://ai-gateway.vercel.sh/claude-code and, on macOS, keeps the key in the Keychain. Claude Code still runs on Claude models; Vercel simply carries and meters the traffic.
Connection 2 — your code calling Jev through AI Gateway. Vercel serves Jev as typesafe-ai/jev through a TypeSafe-compatible API at https://ai-gateway.vercel.sh/typesafe:
curl https://ai-gateway.vercel.sh/typesafe/v1/systemone \
-H "Authorization: Bearer $AI_GATEWAY_API_KEY" \
-H "Content-Type: application/json" \
-d '{
"model": "typesafe-ai/jev",
"state": "I was charged twice for my subscription.",
"questions": {
"refund": {
"type": "noul",
"instructions": "Is the customer asking for money back?"
}
}
}'
So "connecting Claude Code to Jev via Vercel" in practice means: Claude Code runs through the gateway, the TypeSafe skill teaches it the API, and the code it writes calls typesafe-ai/jev with the same key. Our Jev on Vercel AI Gateway guide covers the AI SDK evaluate route and evaluation fallbacks.
How to Install Jev AI in Claude Cowork
First, a timing note that most guides have missed: on September 16, 2026 Anthropic began merging Claude Cowork and chat into one Claude, rolling out to Pro and Max plans first and keeping existing Cowork chats, projects, connectors and skills. "Installing Jev in Cowork" therefore means adding the TypeSafe skill to Claude.
Following Anthropic's Help Center article "Use skills in Claude":
- Make sure Code execution and file creation is on under Settings → Capabilities. Skills depend on it. On Team and Enterprise plans an owner may need to enable skills first.
- Download the
skills/typesafe-aifolder from TypeSafe'stypesafe-ai/skillsrepository on GitHub — the whole folder, including its reference files — and zip it. - In Claude, go to Customize → Skills, click +, then Create skill → Upload a skill, and upload the ZIP.
- Toggle it on, and ask Claude to "use the TypeSafe skill" when you plan a feature.
Set expectations accordingly. In Cowork the skill is most useful for exploring where Jev fits a project and drafting questions and thresholds; the calls themselves belong in your application code with your own key. We found no TypeSafe-published connector in Claude as of September 30. Third-party MCP connectors for Jev exist, but each one sees your prompts and holds your API key — vet the publisher before you connect one.
Is There an Official Jev MCP Server?
No. TypeSafe's documentation index lists the HTTP API, Python and JavaScript SDKs, the agent skill and an n8n node — no MCP server. Community MCP servers and Cursor plugins that expose choice, score and noul as tools do exist on GitHub. They can be convenient for letting an agent ask Jev ad hoc questions, but they are not TypeSafe's, and for anything your product depends on, a direct API call in your own code is easier to review, test and pin to a version.
After the skill and a working API call, the next place to look is the rest of your agent: our guide to using Jev inside an AI agent covers tool selection, argument filling and gating with published numbers.
FAQ
Can I select Jev as a model in Cursor or Claude Code?
No. Jev has no text-generation endpoint for an editor to use. The closest thing is OpenRouter's Jev Router, which uses Jev to pick another model for each request.
Does Jev work with Claude Code?
Yes, as a skill, as a permission hook and as an API your code calls — not as Claude Code's model. The TypeSafe skill installs with two claude plugin commands.
How do I use Jev TypeSafe AI in Cursor?
Install the skill with npx skills add typesafe-ai/skills --skill typesafe-ai, attach it with / in Agent chat, and have Cursor write code that calls the Jev API. Optionally add a beforeShellExecution hook with failClosed to gate shell commands.
Can I use Jev offline for coding?
Not Jev itself; it is hosted only. Ollama's Jev-compatible endpoint lets you develop against a local decision model with the same request shape and swap to hosted Jev later.
Which API key does the TypeSafe skill expect?
TYPESAFE_API_KEY, for TypeSafe's own API. With jev-ai.org or Vercel AI Gateway, give the agent that provider's endpoint and key instead; the request body stays the same.
The Bottom Line
You cannot make Jev your coding model, and you do not need to. The value is in the four setups that put its decisions where they help.
- The TypeSafe skill gets Claude Code, Cursor and Codex writing correct Jev code — install it first.
- A direct API call is what your product actually ships; test it with one
curlbefore anything else. - A permission hook lets Jev clear routine prompts, behind a static risk list and a 0.9 threshold.
- Jev Router is the one documented way for Jev to choose models inside a session — test it on a throwaway project.
Start with the skill and one request. Get a Jev AI API key, run the curl from step 2 in your terminal, and then hand the rest to your agent with our API docs open beside it.
Sources
- Jev with coding agents — TypeSafe AI docs — Why Jev is not a coding-agent LLM, and what to use instead.
- Agent skill — TypeSafe AI docs — Install, update and invoke commands for Claude Code and other agents.
- Auto-Approve Coding Agent Permission Prompts with Jev — OpenRouter — Hook design, configurations for Claude Code, Codex, Cursor and OpenCode, captured scores and cost.
- TypeSafe API with AI Gateway — Vercel — The
typesafe-ai/jevmodel and the TypeSafe-compatible endpoint. - Claude Code and Claude Agent SDK with AI Gateway — Vercel — The setup command and environment variables for routing Claude Code through AI Gateway.
Commands and configuration shapes were checked against each vendor's documentation on September 30, 2026. Scores and per-check costs in the permission-hook section are OpenRouter's captured runs, not ours. The jev-ai.org version of the hook and the Jev Router combinations in step 4 follow from the documentation and have not been tested end to end by us.




