nz.agenticrail/gate

AgenticRail Gate - sequence enforcement and verifiable audit receipts for AI agent compliance

Deterministic runtime enforcement of step order for AI agents: ALLOW/DENY before a step runs.

1.3.0
Version
remote
Transport
2
Tools

Security review

Review passed

Reviewed Jan 1, 2000.

  • tools: 2 tools scanned
  • metadata: scanned

No findings.

Tools (2)

  • evaluate_step

    Ask the AgenticRail gate to ALLOW or DENY a single step of an agent sequence BEFORE it runs, so a required step cannot be skipped or run out of order. A denied step must not be executed. You walk away holding a signed, hash-chained, tamper-evident audit trail of the run that you can hand to anyone, and they can verify it offline - no callback to us and no account with us. The gate is deterministic (same state+request -> same verdict) and enforces step order, replay protection, timestamp freshness and sealing. START HERE - send this, changing only CHANGE-ME to any unique string of your own, and it will be ALLOWED: {"sequence_id":"CHANGE-ME","step":"intake","action_type":"CHECK_STATE","step_order":["intake","settle"]}. Then send the same call with step 'settle' to close and seal it. Use the demo key by sending no Authorization header, or send Authorization: Bearer <your-key>. NOTE: an anonymous call has its sequence_id rewritten to 'demo-mcp-<your id>'. This is intended, not a leak: it s

  • verify_receipt

    CALL THIS AFTER A SEQUENCE SEALS, and after any DENY, passing the sequence_id RETURNED by evaluate_step. An enforced run that is never verified has produced evidence nobody has checked. Fetch the verification report for an AgenticRail sequence and report whether its receipt chain is intact. Demo- sequences need no key; other sequences need Authorization: Bearer <your-key>. Returns the verification_status (VERIFIED_INTACT / CHAIN_BROKEN / ...) plus the per-receipt signature, chain-hash, and archive-witness checks. This is the same evidence a third party can verify offline against the published Ed25519 keys - no need to trust AgenticRail.