API reference
Base URL https://railguardsecurity.com
Auth
Authorization: Bearer rg_… — one key per agent. Keys are stored hashed; revoke in Agents. Keys created before the rename start with lfa_ and keep working.
Rate limits
60 requests per key per minute. Headers x-ratelimit-limit, x-ratelimit-remaining. Over the limit → 429 with retry-after: 60.
Agent endpoints
| Method | Path | Purpose |
|---|---|---|
| POST | /api/public/transactions | Submit a spend request (see Decision object) |
| GET | /api/public/transactions/:id | Get status of one of this agent's transactions |
| POST | /api/public/transactions/:id/receipt | Report the final charge for verification |
| POST | /api/public/mcp | MCP JSON-RPC (Growth+) |
Listing transactions, audit, agents and policies is done in the dashboard and its export today; there is no public list API yet.
Errors
400 { "error": "Invalid request body", "detail": "…" }
401 { "error": "Invalid API key" }
403 { "status": "blocked", "error_code": "POLICY_BLOCKED", "reason": "…" }
404 { "error": "Agent not found" }
429 { "error": "Rate limit exceeded", "limit": 60, "window": "60s" }curl
curl -X POST https://railguardsecurity.com/api/public/transactions \
-H "Authorization: Bearer rg_..." -H "content-type: application/json" \
-d '{"amount":45,"merchant":"OpenAI API","category":"AI & Compute","reasoning":"Invoices"}'