Quickstart
One path, copy-paste, under 5 minutes.
Just want to look first? The public demo runs the same policy engine with sample data — no login.
1. Get a key
- Create an account. You get a sandbox Demo workspace (no real money) and an empty Live workspace.
- In Demo: Agents → Connect agent. Copy the key (starts with
rg_). It is shown once and stored only as a hash.
2. Install
Python
pip install requests
# download guardrail.py from Agents → Connect agent (or /api/public/sdk/python)Node
# download guardrail.ts from Agents → Connect agent (or /api/public/sdk/typescript)
# no dependencies — uses fetch3. Wrap the spend
agent.py
from guardrail import Guardrail, SpendBlocked
guardrail = Guardrail(api_key="rg_...", base_url="https://railguardsecurity.com")
try:
payment = guardrail.spend(
amount=45.00,
merchant="OpenAI API",
category="AI & Compute",
reasoning="Process 500 PDF invoices uploaded by the user.",
rail="stripe",
)
print(payment["status"], payment.get("credential"))
except SpendBlocked as e:
print("Stop or choose an alternative:", e.reason)4. What you should see
Try three amounts against the seeded Demo policies (auto-approve under $100):
| Call | SDK result | In the workspace |
|---|---|---|
| amount=45 | status approved, sandbox card | Transactions: Approved, audit row with reasons |
| amount=250 | waits (flagged) until a human decides | Approvals queue + in-app / Slack alert |
| merchant on blocklist, or over budget | raises SpendBlocked | Transactions: Blocked with the failing rule |
All docs
- Decision object — approved, flagged, blocked and the reasons returned
- Approvals — queue, alerts and signed decision webhooks
- Payment rails — Stripe Issuing, Ramp, USDC (Preview)
- Audit & export — append-only log, retention, CSV/JSON
- API reference — endpoints, auth, rate limits, errors
- SDKs — Python and TypeScript
guardrail - MCP — tools over JSON-RPC
- Idempotency & retries — no second card on retry
- Security — data flow, keys, subprocessors