Skip to content
v1.3What’s new

A runtime firewall for AI agents.

AgentGuard sits on the wire between your agent and its tools and checks every call against your policy before it runs. Open source, self-hosted, no agent code changes.

agentguard cloud · hosted · early access

We’ll only use your email to contact you about AgentGuard. Privacy

open source · self-host it now, free

curl -fsSL https://github.com/Caua-ferraz/AgentGuard/releases/latest/download/install.sh | sh

Installs agentguard, the MCP gateway and the LLM proxy after checking them against the release checksums. Then run agentguard setup.

Read the quickstart

Apache 2.0core license
0.53 msp99 decision, measured
3enforcement paths
5.1Mrequests, zero errors — 3-node
how it works

Three steps. No agent code changes. No new vendor in your data path.

Put the firewall on the wire — at the protocol boundary between the agent and the world. Define policy. Stream the audit. Self-hosted by default — we never see your traffic.

01 / INTERCEPT

Go on the wire.

Point your MCP client at the gateway, or set one base-URL env var so OpenAI / Anthropic SDK traffic flows through the proxy. Every tool call is now policy-checked — including dynamic and model-generated ones.

# agentguard-llm-proxy
export OPENAI_BASE_URL=http://127.0.0.1:8081/v1
02 / DECIDE

Decide in policy.

Rules in YAML across seven scopes — shell, filesystem, network, browser, cost, data, MCP tools. Allow, deny, or pause for human approval; rate limits and spend caps compose on top.

scope: shell
deny: "rm -rf *" · require_approval: "sudo *"
03 / AUDIT

Audit every decision.

Append-only JSONL trail — agent, scope, command, reasoning. Query it by CLI, dashboard, or Prometheus; forward it to WORM storage or your SIEM for tamper evidence. Replay any run end-to-end.

# 14:02:11.482
shell → DENY · audit #4821 · 0.53 ms
architecture

One checkpoint between intent and effect.

The agent issues a tool call; the checkpoint evaluates policy; the call proceeds, pauses for human approval, or is denied. One policy, one audit trail, one approval queue — whether the checkpoint runs as an MCP gateway, an LLM API proxy, or in front of your SDK.

intent agent

network wiki.internal
filesystem read ./docs
browser click submit
shell rm -rf /
shell sudo deploy
enforce
AgentGuard

Policy evaluated at the protocol boundary. One decision per call. Append-only, replayable audit.

YAML policy · append-only audit · human approvals · self-hosted

real systems

wiki.internal · allowed
./docs · allowed
browser · allowed
shell · denied
sudo · pending approval
integrations

Sits between the agent and the tool — wherever the agent runs.

Run it on the wire for zero code changes, or embed the SDK where the wire isn’t practical. Same policy engine, same audit trail, same approval queue on every path.

Wire-levelprotocol boundary · shipping since v0.5

MCP gateway

agentguard-mcp-gateway

JSON-RPC checkpoint between any MCP client and the real MCP server. Every tools/call is policy-checked before it reaches the server. No agent code changes.

  • Claude Desktop
  • Cursor
  • Cline
  • Zed
  • Continue
shipping · v1.3

LLM API proxy

agentguard-llm-proxy

HTTP checkpoint in front of the OpenAI and Anthropic APIs — set one base-URL env var. Tool calls in the response stream are gated against policy, with streaming support.

  • OpenAI API
  • Anthropic API
shipping · v1.3
SDKs + adaptersin-process · compatibility tier
  • LangChainpy · ts
  • CrewAIpy
  • browser-usepy
  • MCPstdio · sse

The SDKs are opt-in by design — the agent calls guard.check(…). Use them when you control the agent’s source; pair them with the wire-level paths when you don’t.

security & deployment

Runs where your data already lives.

We took out the things you don’t want in your security path: an outbound dependency, a vendor with your prompts, a black-box decision. AgentGuard is yours — on your wire, in your infrastructure.

Self-hosted by default

Single binary or library. Runs in your VPC, your container, your laptop — one node on SQLite, or many behind PostgreSQL. There is no SaaS to call.

Your data stays yours

By default, prompts, tool args, and results never leave your network: the runtime makes no outbound calls, sends no telemetry, and runs no update check. If you opt in to the hosted dashboard, you choose what gets sent.

Append-only audit, replayable

Every decision written to an append-only JSONL trail — agent, scope, command, reasoning — with secrets in commands masked before they are written (since v1.2). Forward it to S3 Object Lock, a SIEM, or syslog for tamper evidence. Reconstruct any run end-to-end.

Policy as code

YAML with a stable v1 schema across seven scopes — shell, filesystem, network, browser, cost, data, MCP tools. Reviewable in PRs. Versioned, diff-able, deployable like any service.

pricing

Free forever, if you don’t mind YAML. Paid if you want it run for you.

The full firewall is open source — install, configure, self-host. AgentGuard Cloud is the hosted, multi-tenant version: same policy engine, same audit trail, run for you. Currently in design; the waitlist is open.

Open Source

AgentGuard Core

$0 / forever

The full firewall — wire-level transports, policy engine, approvals, dashboard. Apache 2.0, source on GitHub. You write the YAML, you run the binary, you keep every byte.

  • +Full policy engine — 7 scopes, YAML v1 schema
  • +All three enforcement paths: MCP gateway, LLM API proxy, SDKs
  • +Human-in-the-loop approvals + live dashboard
  • +Append-only audit trail with rotation
  • +Multi-tenant policies — zero-config SQLite or multi-node PostgreSQL
  • +Community support on GitHub issues
faq

Straight answers, no hedging.

The claims below track the open-source repo — when the code changes, this page changes.

Is AgentGuard open source?

Yes. The full runtime — policy engine, wire-level transports, approval queue, and dashboard — is Apache 2.0, source on GitHub. Self-hosted, single binary. AgentGuard Cloud is a separate hosted layer that never gates the open path.

How do I install AgentGuard?

One command. On macOS or Linux: curl -fsSL https://github.com/Caua-ferraz/AgentGuard/releases/latest/download/install.sh | sh. On Windows, in PowerShell: irm https://github.com/Caua-ferraz/AgentGuard/releases/latest/download/install.ps1 | iex. Both install the server, the MCP gateway, and the LLM API proxy after checking them against the release checksums. Then run agentguard setup: a menu that starts AgentGuard at login with a starter policy and an API key, and later updates or uninstalls it. Running the install command again also updates. There is also a multi-arch Docker image, ghcr.io/caua-ferraz/agentguard, and a go install path for Go 1.25+.

What does wire-level enforcement mean?

AgentGuard intercepts at the protocol boundary instead of asking the agent to opt in. The MCP gateway sits between any MCP client (Claude Desktop, Cursor, Cline, Continue, Zed) and the real MCP server, policy-checking every tools/call. The LLM API proxy sits in front of the OpenAI and Anthropic APIs — set one base-URL environment variable and tool calls in the response stream are gated before your code ever sees them.

What happens if AgentGuard cannot read a tool call?

It refuses it. Gating fails closed: a response the proxy cannot decode into a tool call, a stream that ends mid-tool-call, and a tool input that arrives orphaned from its call are all denied under a stable rule string rather than forwarded unexamined. v1.1 closed five such paths in the LLM API proxy — before it, a stream that ended with a tool call still buffered produced an empty 200, and a body an SDK could execute but Go could not decode was passed through. Refusals are recorded in the audit trail with the DENY the client received, and they are deliberately not subject to --fail-mode allow: that flag governs an unreachable guard, not a healthy guard that cannot see what the client will execute.

Does AgentGuard see my prompts or tool data?

No. AgentGuard is self-hosted and makes no outbound calls by default. Prompts, tool arguments, and results stay in your network unless you configure notifications (Slack, webhooks) or opt in to AgentGuard Cloud.

How fast is a policy decision?

0.53 ms p99, measured end-to-end on the full HTTP check path with persistence enabled (the v1.0 verification). A CI gate fails the build of every release if p99 crosses the 3 ms budget; v1.2's command-by-command shell checks left the simple-command path at v1.1's speed.

Can AgentGuard run across multiple replicas?

Yes, since v1.0, and hardened in v1.1. The zero-config default is single-node SQLite; point --store-dsn at PostgreSQL and give each replica a --node-id to share approval, rate-limit, and cost state across nodes. Reconciliation runs in the background — no synchronous database call is added to the /v1/check hot path, so the sub-3 ms p99 budget is preserved. v1.1 added an advisory lock so replicas no longer race each other through schema migration at boot, and a shared row-lock order that removed cross-node flush deadlocks: a three-node cluster served 5.1M requests across three runs with zero errors and zero deadlocks, where the pre-fix build of the same shape produced 393. Distributed rate limiting is bounded-overshoot by design, and conflicting approval resolutions always converge to DENY.

Is the audit log tamper-proof?

AgentGuard writes an append-only JSON-Lines audit trail of every decision — agent, scope, command, reasoning. It does not cryptographically seal the log itself; for tamper evidence, forward the trail to append-only/WORM storage such as S3 Object Lock, a SIEM, or syslog.

Is AgentGuard a sandbox?

No. AgentGuard is a policy-enforcement and audit layer, not an OS sandbox — it does not intercept syscalls. Combine it with OS-level isolation (containers, seccomp, egress rules) when your threat model includes a hostile agent that controls its own runtime. As of v1.1 this is written down rather than implied: docs/THREAT_MODEL.md states the actors in decreasing order of trust, the trust boundaries between them, the fail-open versus fail-closed matrix, and the explicit non-goals.

roadmap

Where we are. Where we’re going.

Built in public. Shipped against a thesis, not a press release.

Q1 · 2026

Open source

  • AgentGuard v0.1 published — Apache 2.0, public repo
  • v0.4: security hardening, conditional rules
Q2 · 2026

Wire-level

  • v0.5: MCP gateway + LLM API proxy — enforcement at the protocol boundary
  • v0.6: persistent multi-tenant state on zero-config SQLite
Now · v1.3

Hardened, and easy to run

  • Multi-node on PostgreSQL, fail-closed gating, and v1.2's command-by-command shell checks
  • v1.3: one-command install on Linux, macOS and Windows, and agentguard setup to run, update or remove it
Next · Cloud

AgentGuard Cloud

  • Hosted control plane — central dashboard and audit sync across your agent fleet
  • In design — waitlist open

Ship agents like you ship code.

policy precedes action · lex antecedit actum

Want AgentGuard run for you? Join the AgentGuard Cloud waitlist — design partners go first. The open-source core stays free, forever.

We’ll only use your email to contact you about AgentGuard. Privacy