RailGuardDocs

API reference

Base URL https://railguardsecurity.com

Auth

Authorization: Bearer rg_… — one key per agent. Keys are stored hashed; revoke in Agents. Keys created before the rename start with lfa_ and keep working.

Rate limits

60 requests per key per minute. Headers x-ratelimit-limit, x-ratelimit-remaining. Over the limit → 429 with retry-after: 60.

Agent endpoints

MethodPathPurpose
POST/api/public/transactionsSubmit a spend request (see Decision object)
GET/api/public/transactions/:idGet status of one of this agent's transactions
POST/api/public/transactions/:id/receiptReport the final charge for verification
POST/api/public/mcpMCP JSON-RPC (Growth+)

Listing transactions, audit, agents and policies is done in the dashboard and its export today; there is no public list API yet.

Errors

400 { "error": "Invalid request body", "detail": "…" }
401 { "error": "Invalid API key" }
403 { "status": "blocked", "error_code": "POLICY_BLOCKED", "reason": "…" }
404 { "error": "Agent not found" }
429 { "error": "Rate limit exceeded", "limit": 60, "window": "60s" }
curl
curl -X POST https://railguardsecurity.com/api/public/transactions \
  -H "Authorization: Bearer rg_..." -H "content-type: application/json" \
  -d '{"amount":45,"merchant":"OpenAI API","category":"AI & Compute","reasoning":"Invoices"}'