AgenticRail Gate - sequence enforcement and verifiable audit receipts for AI agent compliance
Deterministic runtime enforcement of step order for AI agents: ALLOW/DENY before a step runs.
- 1.3.0
- Version
- remote
- Transport
- 2
- Tools
Security review
Review passedReviewed Jan 1, 2000.
- tools: 2 tools scanned
- metadata: scanned
No findings.
Tools (2)
evaluate_step
Ask the AgenticRail gate to ALLOW or DENY a single step of an agent sequence BEFORE it runs, so a required step cannot be skipped or run out of order. A denied step must not be executed. You walk away holding a signed, hash-chained, tamper-evident audit trail of the run that you can hand to anyone, and they can verify it offline - no callback to us and no account with us. The gate is deterministic (same state+request -> same verdict) and enforces step order, replay protection, timestamp freshness and sealing. START HERE - send this, changing only CHANGE-ME to any unique string of your own, and it will be ALLOWED: {"sequence_id":"CHANGE-ME","step":"intake","action_type":"CHECK_STATE","step_order":["intake","settle"]}. Then send the same call with step 'settle' to close and seal it. Use the demo key by sending no Authorization header, or send Authorization: Bearer <your-key>. NOTE: an anonymous call has its sequence_id rewritten to 'demo-mcp-<your id>'. This is intended, not a leak: it s
verify_receipt
CALL THIS AFTER A SEQUENCE SEALS, and after any DENY, passing the sequence_id RETURNED by evaluate_step. An enforced run that is never verified has produced evidence nobody has checked. Fetch the verification report for an AgenticRail sequence and report whether its receipt chain is intact. Demo- sequences need no key; other sequences need Authorization: Bearer <your-key>. Returns the verification_status (VERIFIED_INTACT / CHAIN_BROKEN / ...) plus the per-receipt signature, chain-hash, and archive-witness checks. This is the same evidence a third party can verify offline against the published Ed25519 keys - no need to trust AgenticRail.