v0.1.0-alpha · open source · testnet

Stop agent payment mistakes before they become losses.

Railguard applies policy before a wallet signs, tracks uncertain broadcasts, and produces tamper-evident execution records—without taking custody.

simulate → protect → 6/6 blocked → sample receipt

agent_17

wants 500 USDC

RAILGUARD
  • POLICYALLOW
  • RESERVE500 USDC
  • EXECUTEtx_82af
  • OBSERVECONFIRMED
  • RECONCILEMATCHED
  • EVIDENCESEALED
EXECUTION SIMULATION
12:41:08.201INTENTagent_17500 USDC
12:41:08.218POLICYrecipient_allowedALLOW
12:41:08.231RESERVEgrant_8f2cLOCKED
12:41:08.902EXECUTE0x89ad…f21aSUBMITTED
12:41:10.004OBSERVEBase SepoliaCONFIRMED
12:41:10.104RECONCILEamount+recipientMATCHED
12:41:10.118EVIDENCErg_82KFSEALED

Watch Railguard decide

On supported execution rails, stored payments follow the same financial-control lifecycle.

Intent

Agent requests a bounded payment — amount, asset, recipient, task scope.

Authorize

Policy evaluates recipient lists, budgets, and assurance mode before funds move.

Reserve

USDC is committed before execution so races and double-spends fail closed.

Execute

Settlement rail submits through your existing signer and wallet stack.

Observe

Chain and RPC reality is watched — including UNKNOWN after broadcast.

Reconcile

On-chain transfer is matched to intent; mismatches surface as reconciliation required.

Evidence

Hash-chained envelope you can verify with railguard receipts.

LIFECYCLE TRACE
12:41:08.201INTENTagent_17500 USDC
12:41:08.218POLICYrecipient_allowedALLOW

Failure Lab

Interactive failure simulation — six canonical classes. Client-side animation, not live payment execution. Same story as the executable Atlas and railguard attack.

unsafe-agent · treasury

$ railguard attack

Simulate attacks, then railguard protect, then simulate again.

  • APF-001 REPLAY—
  • APF-002 BUDGET RACE—
  • APF-003 CRASH AFTER BROADCAST—
  • APF-004 SETTLEMENT MISMATCH—
  • APF-005 STALE AUTH—
  • APF-006 POLICY BYPASS—
SIMSIMULATION TRACE

Press Simulate attack to run the client-side trace…

One firewall. Different money flows.

Same five CLI verbs — scan · attack · protect · status · receipts — run in your terminal after clone & install (bun run railguard …). Built first for agent developers and treasury operators; security properties are shown in the Failure Lab and repo tests. Agent tools use MCP, not these shell lines.

Developer

Ship agent payments without learning treasury ops

Terminal command

# Terminal — after clone & bun install (repo root)

bun run railguard scan

bun run railguard attack

AI agent

Tool-using agents with spend authority

SDK call (TypeScript — not a shell command)

# Terminal — after clone & bun install (repo root)

railguard check(intent)

Treasury ops

Finance controls before USDC leaves custody

Terminal command

# Terminal — after clone & bun install (repo root)

bun run railguard protect

Startup ops

Terminal command

# Terminal — after clone & bun install (repo root)

bun run railguard receipts <id>

DAO

Terminal command

# Terminal — after clone & bun install (repo root)

bun run railguard status

Stablecoin business

Terminal command

# Terminal — after clone & bun install (repo root)

bun run railguard attack --profiles APF-004

Trading bot

Terminal command

# Terminal — after clone & bun install (repo root)

bun run railguard attack --profiles APF-002

Creator / team

Terminal command

# Terminal — after clone & bun install (repo root)

bun run railguard scan

Personal

Terminal command

# Terminal — after clone & bun install (repo root)

bun run railguard protect

CLI, MCP, and API — same lifecycle

Lines that start with $ are terminal commands (PowerShell, bash, or Windows Terminal). JSON blocks are config files for Cursor or Claude Desktop — do not paste them into a shell. Packages are developed in the open repo; there is no public npx @railguard/cli yet.

Install (terminal)

# One-time — requires Bun from https://bun.sh

git clone https://github.com/prasanthkuna/railguard-gateway.git

cd railguard-gateway

bun install

CLI

Humans, CI, and demos — authorize, execute, verify from the terminal.

Verbs: scan · attack · protect · status · receipts

Terminal command

# Terminal — after clone & bun install (repo root)

bun run railguard doctor

bun run railguard attack

packages/cli README

MCP (agents in Cursor / Claude)

Tool calls for create_intent, authorize, verify — same API as the CLI.

MCP config (JSON) — paste into editor, not a shell command
{
  "mcpServers": {
    "railguard": {
      "command": "bun",
      "args": ["run", "packages/mcp/src/server.ts"],
      "env": {
        "RAILGUARD_BASE_URL": "http://127.0.0.1:4000",
        "RAILGUARD_ACCESS_TOKEN": "<your-token>"
      }
    }
  }
}
Run MCP server (terminal)

# Terminal — after clone & bun install (repo root)

# Terminal 1: bun run dev:api — then start MCP in Terminal 2

bun run railguard:mcp

Full example + tool list

REST + TypeScript SDK

Backend services and the operator UI call /v1/* directly.

Verify testnet evidence (terminal)

# Terminal — after clone & bun install (repo root)

bun run arbitrum-sepolia-evidence

Integration guide · Stellar proof · Arbitrum proof

Evidence

Stored Railguard executions produce a tamper-evident envelope — intent, policy, settlement, hash chain.

View verified testnet proofView sample receipt

Execution infrastructure

Logos are trademarks of their respective owners. Railguard is an independent open-source project.

One control model across supported and planned rails

Railguard keeps the control model constant while execution infrastructure changes.

Coinbase CDP

● INTEGRATED
  • Policy✓
  • Reservation✓
  • Execution✓
  • Reconciliation✓

Failure coverageAPF-003 · APF-004 · APF-005

Reference testnet console + CDP execution path on Base Sepolia.

Integration details →

Try: railguard protect

Base

● TESTNET VERIFIED
  • Policy✓
  • Reservation✓
  • Execution✓
  • Reconciliation✓

Failure coverageAPF-003 · APF-004 · APF-005

Last proof
2026-09-28
Transactions
12
Failures tested
3
Evidence
VERIFIED

Base Sepolia reference execution via CDP.

Integration details →

Try: railguard verify <executionId>

Arbitrum

● SEPOLIA VERIFIED
  • Policy✓
  • Execution✓
  • Observe✓
  • Reconcile✓
  • Evidence✓

Failure coverageAPF-003 · APF-004

Last proof
2026-09-30
Evidence
VERIFIED

Hook contracts deployed on Sepolia; separately, external-wallet 0.01 USDC verified via operator lifecycle (two independent proofs).

Integration details →

Try: bun run arbitrum-sepolia-evidence

Monad

● SETTLEMENT VERIFY
  • Policy✓
  • Reservation✓
  • Execution✓
  • Reconciliation✓

Failure coverageAPF-002 · APF-003 · APF-005

Monad testnet executor via EVM settlement-verify rail.

Integration details →

Try: railguard attack

Arc (Circle)

● SETTLEMENT VERIFY
  • Policy✓
  • USDC execution✓
  • Reconciliation✓

Failure coverageAPF-003 · APF-004

Circle Arc USDC settlement-verify on testnet.

Integration details →

Try: bun run arc-testnet-evidence

Stellar

● HORIZON CONFIRMED
  • Policy✓
  • Execution✓
  • Observe✓
  • Reconcile✓
  • Evidence✓

Failure coverageAPF-001 · APF-003 · APF-004

Last proof
2026-10-04
Evidence
VERIFIED

Native XLM payment on testnet verified via Horizon (CONFIRMED); public proof page + committed manifest.

Integration details →

Try: bun run stellar-testnet-evidence

Failure Lab

● SHIPPED
  • APF-001…006✓
  • SARIF✓
  • CI reproduction✓

Failure coverageAPF-001 · APF-002 · APF-003 · APF-004 · APF-005 · APF-006

Six financial failure classes — attack, protect, and reproduce in the open lab.

Integration details →

Try: railguard attack

x402

● ADAPTER
  • Pre-sign policy✓
  • Replay✓
  • Rolling budgets✓

Failure coverageAPF-001 · APF-002

Execution rail inside Gateway — not a separate product.

Integration details →

Try: railguard attack

Celo

● ROADMAP
  • Policy—
  • Agent payments—
  • Verification—

Failure coverageAPF-001 · APF-004

Celo agent-economy verification via EVM settlement-verify (roadmap).

Integration details →

Try: railguard check

Airwallex

● ROADMAP
  • Policy—
  • Fiat API execution—
  • Reconciliation—

Failure coverageAPF-003 · APF-005

Fiat/agentic banking executor on the same correctness core (integration planned).

Integration details →

Try: railguard protect

All ecosystems →

Open source

$ railguard attack

  • no account
  • self-hostable Gateway
  • inspect every policy decision
  • build your own execution rail
Your Agent
    ↓
Railguard
    ↓
Your Signer
    ↓
Your Chain

Railguard does not custody your funds or private keys. It sits between agent intent and your signer or wallet provider.

Evaluate Railguard seriously

Three steps: simulate a failure class, inspect verified testnet proof, then run the gateway locally against staging or your own signer.

Verify pack locally (terminal)

# Terminal — after clone & bun install (repo root)

bun run verify-arbitrum-sepolia-pack

bun run verify-stellar-testnet-pack

bun run railguard verify

Read the architecture · Quick start · Request a pilot

Give agents authority. Not unlimited money.

Open-source financial execution firewall for autonomous software.