This is an in-browser policy simulation. Its throwaway-key Ed25519 records cover simulated metadata, not real refunds or court-admissible evidence. Disclaimer.
home / drive the refund agent
Local simulation · throwaway browser key

Exercise a refund policy without moving money.

Below is a customer-refund simulation with an Ed25519 keypair generated in this tab. Drive it: allow a small simulated request, push it past the $500/day cap, try a payment_execute action while declaring read_only, or activate the simulated zero-cap stop. Every simulated evaluation is hashed into a chained record signed by the throwaway browser key.

policy
refund-agent-v1 · enforce
demo capability claim
read_only
daily cap · spent
$0.00 / $500.00
zero-cap stop
READY · simulation active
refund agent · actionsread_only
routine refunds
push the policy
custom refund
$
change local demo state
agentguard · decision logseq none
› keypair ready. choose a simulated action on the left.

The simulation and signing above run in your browser. The inline demo code does not transmit its action metadata or private key. It loads cryptographic modules from jsDelivr and fonts from Google. If you click “Verify chain on /verify,” the signed chain and public key are placed in the AgentGuard URL for a separate browser verification; the private key is not. The record demonstrates integrity of simulated metadata under the displayed throwaway public key, not that a refund or human approval occurred.

this session's signer public key: generating…
What just happened

Signed allow and block records can both be checked.

01 · signed in-browser

Real Ed25519, real chain

Each simulated decision is canonicalized, SHA-256 hashed into an entryHash, signed over that hash, and linked to the previous entry by previousHash. The tamper button changes a signed field and shows the resulting hash mismatch.

02 · block is a receipt too

The browser signer records blocks

When the simulation exceeds the cap or declares insufficient capability, the page signs a BLOCK record with its throwaway key. The record shows what this page evaluated; it is not an AgentGuard production receipt.

03 · verify it elsewhere

Don't trust this page

Every receipt card has a “Verify on /verify” link that re-checks the signature and chain on a separate page, and a copy button so you can verify it from your own terminal.

Real terminal run

Watch the rogue agent hit every brake.

The recorded deterministic SDK run blocks $96.00 of projected API spend. Separately, it blocks a simulated $9,000.00 wire because the declared capability is insufficient. A zero-cap policy blocks the next call, the signed receipt chain verifies, and a tampered receipt fails verification.

Terminal recording of AgentGuard blocking projected spend, refusing an insufficient-capability wire fixture, applying a zero-cap policy, verifying receipts, and detecting tampering
The full brief

Everything behind this demo, on one page.

The registered mark, patent-pending status, the live SDK and MCP server, three implemented DAG-trust demonstrations, and the roadmap. For the founder who wants to take it over, or the team that wants to acquire it.

AgentGuard one-pager preview