Intent
Agent requests a bounded payment — amount, asset, recipient, task scope.
v0.1.0-alpha · open source · testnet
Railguard applies policy before a wallet signs, tracks uncertain broadcasts, and produces tamper-evident execution records—without taking custody.
simulate → protect → 6/6 blocked → sample receipt
wants 500 USDC
On supported execution rails, stored payments follow the same financial-control lifecycle.
Agent requests a bounded payment — amount, asset, recipient, task scope.
Policy evaluates recipient lists, budgets, and assurance mode before funds move.
USDC is committed before execution so races and double-spends fail closed.
Settlement rail submits through your existing signer and wallet stack.
Chain and RPC reality is watched — including UNKNOWN after broadcast.
On-chain transfer is matched to intent; mismatches surface as reconciliation required.
Hash-chained envelope you can verify with railguard receipts.
Interactive failure simulation — six canonical classes. Client-side animation, not live payment execution. Same story as the executable Atlas and railguard attack.
$ railguard attack
Simulate attacks, then railguard protect, then simulate again.
Press Simulate attack to run the client-side trace…
Same five CLI verbs — scan · attack · protect · status · receipts — run in your terminal after clone & install (bun run railguard …). Built first for agent developers and treasury operators; security properties are shown in the Failure Lab and repo tests. Agent tools use MCP, not these shell lines.
Ship agent payments without learning treasury ops
# Terminal — after clone & bun install (repo root)
bun run railguard scan
bun run railguard attack
Tool-using agents with spend authority
# Terminal — after clone & bun install (repo root)
railguard check(intent)
Finance controls before USDC leaves custody
# Terminal — after clone & bun install (repo root)
bun run railguard protect
# Terminal — after clone & bun install (repo root)
bun run railguard receipts <id>
# Terminal — after clone & bun install (repo root)
bun run railguard status
# Terminal — after clone & bun install (repo root)
bun run railguard attack --profiles APF-004
# Terminal — after clone & bun install (repo root)
bun run railguard attack --profiles APF-002
# Terminal — after clone & bun install (repo root)
bun run railguard scan
# Terminal — after clone & bun install (repo root)
bun run railguard protect
Lines that start with $ are terminal commands (PowerShell, bash, or Windows Terminal). JSON blocks are config files for Cursor or Claude Desktop — do not paste them into a shell. Packages are developed in the open repo; there is no public npx @railguard/cli yet.
# One-time — requires Bun from https://bun.sh
git clone https://github.com/prasanthkuna/railguard-gateway.git
cd railguard-gateway
bun install
Humans, CI, and demos — authorize, execute, verify from the terminal.
Verbs: scan · attack · protect · status · receipts
# Terminal — after clone & bun install (repo root)
bun run railguard doctor
bun run railguard attack
Tool calls for create_intent, authorize, verify — same API as the CLI.
{
"mcpServers": {
"railguard": {
"command": "bun",
"args": ["run", "packages/mcp/src/server.ts"],
"env": {
"RAILGUARD_BASE_URL": "http://127.0.0.1:4000",
"RAILGUARD_ACCESS_TOKEN": "<your-token>"
}
}
}
}# Terminal — after clone & bun install (repo root)
# Terminal 1: bun run dev:api — then start MCP in Terminal 2
bun run railguard:mcp
Backend services and the operator UI call /v1/* directly.
# Terminal — after clone & bun install (repo root)
bun run arbitrum-sepolia-evidence
Stored Railguard executions produce a tamper-evident envelope — intent, policy, settlement, hash chain.
Execution infrastructure
Logos are trademarks of their respective owners. Railguard is an independent open-source project.
Railguard keeps the control model constant while execution infrastructure changes.
Failure coverageAPF-003 · APF-004 · APF-005
Reference testnet console + CDP execution path on Base Sepolia.
Try: railguard protect
Failure coverageAPF-003 · APF-004 · APF-005
Base Sepolia reference execution via CDP.
Try: railguard verify <executionId>
Failure coverageAPF-003 · APF-004
Hook contracts deployed on Sepolia; separately, external-wallet 0.01 USDC verified via operator lifecycle (two independent proofs).
Try: bun run arbitrum-sepolia-evidence
Failure coverageAPF-002 · APF-003 · APF-005
Monad testnet executor via EVM settlement-verify rail.
Try: railguard attack
Failure coverageAPF-003 · APF-004
Circle Arc USDC settlement-verify on testnet.
Try: bun run arc-testnet-evidence
Failure coverageAPF-001 · APF-003 · APF-004
Native XLM payment on testnet verified via Horizon (CONFIRMED); public proof page + committed manifest.
Try: bun run stellar-testnet-evidence
Failure coverageAPF-001 · APF-002 · APF-003 · APF-004 · APF-005 · APF-006
Six financial failure classes — attack, protect, and reproduce in the open lab.
Try: railguard attack
Failure coverageAPF-001 · APF-002
Execution rail inside Gateway — not a separate product.
Try: railguard attack
Failure coverageAPF-001 · APF-004
Celo agent-economy verification via EVM settlement-verify (roadmap).
Try: railguard check
Failure coverageAPF-003 · APF-005
Fiat/agentic banking executor on the same correctness core (integration planned).
Try: railguard protect
$ railguard attack
Your Agent
↓
Railguard
↓
Your Signer
↓
Your ChainRailguard does not custody your funds or private keys. It sits between agent intent and your signer or wallet provider.
Three steps: simulate a failure class, inspect verified testnet proof, then run the gateway locally against staging or your own signer.
# Terminal — after clone & bun install (repo root)
bun run verify-arbitrum-sepolia-pack
bun run verify-stellar-testnet-pack
bun run railguard verify
Open-source financial execution firewall for autonomous software.