Govern your agents without renting governance from your model's vendor.
AgentGuard runs as a library inside your runtime: no AgentGuard inference proxy. Supported bindings evaluate spend policy before provider dispatch, record governed decisions, and can sign and hash-chain those records when Ed25519 keys are configured. Self-hosted model costs require an explicit model-cost entry.
Prompts and provider credentials travel directly from your runtime to the provider you select; they do not traverse AgentGuard infrastructure. A configured signing private key stays in your runtime.
Agent traffic spreads across providers and self-hosted models. Then finance asks for attribution.
Cheap tokens didn't reduce the problem. They multiplied it. Teams run parallel agents across a mix of frontier APIs, open-weight models, and self-hosted GPUs. Spend fragments; attribution disappears; nobody can prove what each agent did or spent.
You can't rent governance from a vendor you might compete with.
Frontier labs watch where value accrues on top of their models, then move in: Figma → Claude Design, Cursor → Claude Code. Your spend governance and audit trail shouldn't be owned by the vendor that may one day compete with you. And a proxy sees only its own traffic: it can't gate a cross-agent chain, and it can't see a token it never routed.
In-process controls, one npm install.
Pre-dispatch spend caps
Block or downgrade a supported call before provider dispatch. Caps attached to the configured scope key are evaluated together, with the most restrictive action winning.
See the quickstart →Signed, tamper-evident ledger
Configure Ed25519 keys and a decision store to sign and hash-chain guarded decisions in your runtime. A verifier with the trusted public key can check the chain offline.
Verify a receipt →Multi-agent attestation
A policy can require a signed DAG for selected capability claims. The SDK verifies trusted signer keys, DAG integrity, depth, and composite trust before honoring that claim.
Watch the demo →Dark-token cost attribution
Aggregate recorded estimates by hour, model, and configured scope, including self-hosted models with explicit cost entries. Decision signing is optional and separate from attribution.
Read the docs →Governance that follows the model, even your own weights.
- Change remote or self-hosted models while keeping one configured scope key and decision store. With signing keys configured, appended decisions remain in one verifiable chain.
- Works when inference is local: a proxy can't sit in the path of your own GPUs; a library can.
- Framework middleware for the AI SDK, LangChain, OpenRouter, and Claude Code: insert as a governance layer and inherit your existing stack.
- Policy and receipt primitives are packaged for teams that do not want to build the same controls from scratch.
AgentGuard® Reg. No. 8281464 · Patent-pending · Dunecrest Ventures Inc.