Calls made through a supported binding are evaluated against the policy you set. Configure signing keys when you need a verifiable decision record.
Pick your business and configure a governed AI team.
Supported guarded calls run under configured policy. With signing keys, each content-free metadata record can be checked with the public key.
Once the verifier code and public key are local, receipt integrity can be checked without an AgentGuard server.
npx @agentguard-run/spend demo. This hosted endpoint signs with the site key. See integration examples →Verifiable by design
Now: workflow-level caps
A three-day workflow can burn through tokens before anyone notices the loop. AgentGuard gives the run one budget envelope, resumable checkpoints, and a receipt chain validated before continuing.
For developers
Use the TypeScript SDK or verify a signed receipt in the browser. The SDK evaluates policy in your process before provider dispatch.
Powered by OpenRouter. Works with OpenAI, Anthropic, Bedrock, and any OpenAI-compatible endpoint.
Running open-source models on your own hardware? Signed records capture the resolved model ID, registry weights origin, and configured hosting jurisdiction. Sovereign AI governance →
Governing a multi-agent payment capability? See a static walkthrough of the SDK gate: the runnable local example grants an intact signed chain and denies an altered one. No payment is sent. Open the attestation walkthrough →
See it: an AI agent tries to go rogue and gets caught, with receipts you verify yourself. Drive the demo → Verify a receipt →
AgentGuard for Claude Code: impulse control for your coding agent. See the docs →
Route. Govern. Verify.
The router selects a capable model, applies the configured cap, and can try a fallback provider. With signing keys configured, it appends a receipt. AgentGuard maps law, accounting, insurance, real estate, and e-commerce outcomes to model and reasoning-effort routes built from the OpenRouter catalog.
High-stakes steps can require a second pass: a configurable rule escalates to a higher-effort review before the action is allowed.
The site refreshes its OpenRouter catalog daily. Regulated-vertical rules can exclude China-origin model families before selection.
AgentGuard evaluates configured spend, workflow, and declared-capability limits before supported provider dispatch. When signing keys are configured, it can append a content-free decision record.
“Agents make a billion requests in three seconds, so you need approval flows, inboxes that summarize what happened, logs, and easy rollback.” Dan Shipper · Every podcast · May 2026
Calls made through a supported binding are evaluated in process before provider dispatch.
No AgentGuard inference proxy.
Both paths use the same in-process policy checks. Ed25519 receipt signing is available when keys are configured, and governed-call prompts do not pass through AgentGuard infrastructure.
No AgentGuard inference proxy in either path.
"An AI consultant tells Axios one of their clients recently spent half a billion dollars in a single month after failing to put usage limits on Claude licenses for employees."
A guarded call can be refused before provider dispatch when projected spend exceeds a blocking cap. The circuit breaker can also block repeated call fingerprints, plan churn without progress, and configured reasoning-step limits.
For a governed call with known pricing, AgentGuard projects token cost before dispatch. It records scope and cost metadata in a signed ledger when keys are configured. Prompt content and provider keys go directly to the selected provider, not through an AgentGuard inference proxy.
A supported binding evaluates the governed call before dispatch. In enforce mode, a call that exceeds a configured blocking cap is not sent to the provider and cannot incur that provider call's charge.
The TypeScript package exports bindings for OpenAI, OpenRouter, Anthropic, Bedrock, LangChain.js, Vercel AI SDK, Claude Code, Hermes, and Hermes Kanban. The Python package separately includes OpenAI, Anthropic, Bedrock, OpenRouter, LangChain, CrewAI, LlamaIndex, Hermes, and Hermes Kanban integrations.
npm install @agentguard-run/spend · Python SDK: pip install agentguard-spend · Cross-language byte-identical canonical JSON + Ed25519 signatures.
Paste the prompt below into Claude, GPT, Cursor, Cline, Continue, Devin, or any AI coding assistant. The assistant reads agentguard.run/llms.txt and generates the integration code for your specific provider and framework.
When the agent fleet runs in your stack, the policy can run there too: a library in your process, caps enforced before dispatch, and an optional signed ledger in your storage. AgentGuard does not proxy provider traffic.
|
EMBED IT: OEM LICENSING
Building software for clients with agent fleets? Configure per-client scopes and signed metadata records.
For local or air-gapped deployments, core policy evaluation and receipt verification can run offline. Optional license, consent, telemetry, catalog, managed-key, and timestamp features are separate networked paths.
Contact us to discuss embedded licensing.
|
OEM inquiry → |
Create a distinct guard or policy for each user, agent, or team while reusing the same provider account. Each policy has one compound scope key. With signing configured, records bind the caller-supplied scope and cost metadata.
Caps inside one policy are evaluated together, and the most restrictive triggered action wins. Applications compose separate policies when they need both actor-specific and aggregate limits.
AgentGuard Spend is the live primitive in a broader AgentGuard agent-compliance roadmap, alongside additional agent-governance capabilities in development.
see the full architecture →With Ed25519 keys configured, changing a signed field invalidates receipt verification. A valid signature establishes key possession and record integrity, not the truth of an external event.
Exports integrations for LangChain.js, Claude Code, Vercel AI SDK, OpenRouter, OpenAI, Anthropic, Bedrock, Hermes, and Hermes Kanban. Custom stacks can use the core policy and store interfaces.
Spend policy is enforced in the application process. Configure signing keys when reviewers also need a cryptographically verifiable decision record.
The distinct DAG receipt path links signed nodes to explicit parents. A verifier checks node integrity, signatures, parent references, sequence uniqueness, and cycles offline.
Local-runtime spend caps and capability-gated model routing. Separate bindings cover OpenAI-compatible chat completions, Anthropic Messages, and Bedrock InvokeModel. Signing keys enable Ed25519-signed, hash-chained decision records.
npm install @agentguard-run/spend →The supplied Spend package includes linear decision logs and a distinct parent-linked DAG receipt module. Changes to signed fields invalidate verification.
Integration guide →Open-source chargeback receipt package compiler for Stripe / Visa CE 3.0 disputes. MIT-licensed npm package. Builds signed receipt packages locally, never submits, never proxies. Sibling to Spend in the AgentGuard family.
npm install @merchantguard/agentguard-cb →14 custom agent skills managing Dunecrest's production properties without human intervention. 5 scheduled jobs run continuously: infrastructure health monitoring, CVE scanning across active repos, evidence harvesting, shadow QA verification, and cloud billing audit. The same agent architecture that ships in the AgentGuard SDK, running on our own stack.
Multi-agent workflows produce a cryptographically linked attestation graph.
Each node is checked under a trusted public key. Changes to signed fields invalidate verification.
Start with the local SDK, the signed demo, or an intake conversation. Provider traffic does not pass through an AgentGuard inference proxy.
Local-runtime spend caps with separate provider bindings and optional Ed25519 receipts. The package license permits production up to 10K enforcement calls per calendar month.
An x402-compatible runtime can inspect the catalog. Purchases work only when the response reports active payments and the settlement dependencies are configured.
For bulk seats, custom postures, or evaluating AgentGuard for strategic acquisition, reach our intake team.
Email our intake team →