For platform & infra leads

Govern your agents without renting governance from your model's vendor.

AgentGuard runs as a library inside your runtime: no AgentGuard inference proxy. Supported bindings evaluate spend policy before provider dispatch, record governed decisions, and can sign and hash-chain those records when Ed25519 keys are configured. Self-hosted model costs require an explicit model-cost entry.

Prompts and provider credentials travel directly from your runtime to the provider you select; they do not traverse AgentGuard infrastructure. A configured signing private key stays in your runtime.

npm install @agentguard-run/spend Watch the attestation demo → Verify a receipt →
no AgentGuard inference proxyoptional Ed25519 signingworks with OpenAI · Anthropic · Bedrock · OpenRouter · self-hosted
The reckoning is here

Agent traffic spreads across providers and self-hosted models. Then finance asks for attribution.

Cheap tokens didn't reduce the problem. They multiplied it. Teams run parallel agents across a mix of frontier APIs, open-weight models, and self-hosted GPUs. Spend fragments; attribution disappears; nobody can prove what each agent did or spent.

What AgentGuard records: the configured scope, model, estimated cost, decision, and provenance metadata for guarded calls. Self-hosted estimates use the model-cost entry supplied by the operator.
Why not native provider controls, or a proxy

You can't rent governance from a vendor you might compete with.

Frontier labs watch where value accrues on top of their models, then move in: Figma → Claude Design, Cursor → Claude Code. Your spend governance and audit trail shouldn't be owned by the vendor that may one day compete with you. And a proxy sees only its own traffic: it can't gate a cross-agent chain, and it can't see a token it never routed.

"You can't rent intelligence from the same place that rents it to your competitor."the AI-sovereignty argument now driving enterprise buying decisions
What you get

In-process controls, one npm install.

Pre-dispatch spend caps

Block or downgrade a supported call before provider dispatch. Caps attached to the configured scope key are evaluated together, with the most restrictive action winning.

See the quickstart →

Signed, tamper-evident ledger

Configure Ed25519 keys and a decision store to sign and hash-chain guarded decisions in your runtime. A verifier with the trusted public key can check the chain offline.

Verify a receipt →

Multi-agent attestation

A policy can require a signed DAG for selected capability claims. The SDK verifies trusted signer keys, DAG integrity, depth, and composite trust before honoring that claim.

Watch the demo →

Dark-token cost attribution

Aggregate recorded estimates by hour, model, and configured scope, including self-hosted models with explicit cost entries. Decision signing is optional and separate from attribution.

Read the docs →
Built for a headless, multi-model world

Governance that follows the model, even your own weights.

Start the quickstart → Watch the attestation demo →
All terminology (receipt, audit log, attestation, evidence) describes cryptographically-signed software records, not legal definitions or guarantees of compliance.

AgentGuard® Reg. No. 8281464 · Patent-pending · Dunecrest Ventures Inc.