Skip to content

Public API

These names are the supported API. Everything else is internal and may change between 0.x releases. Breaking changes are listed in the changelog.

agentguard

Name Kind Purpose
Guard(policy, audit="agentguard.jsonl", *, mode, agent_id, context, approval, approval_timeout, judge, rate_limiter) class The interception point. audit is a path or an AuditLogger. See below.
GuardDenied exception A call was denied; .decision holds the details
ApprovalPending exception A GuardDenied for a call queued for a human; .request_id
GuardError exception Infrastructure or execution failure; base of GuardDenied
Decision dataclass effect, policy_result, risk_score, reasons, strong_approval
Effect enum ALLOW, ASK, DENY
Action model The normalized call given to approvers, judges, executors and verifiers
Approval, ApprovalProvider dataclass, protocol Approval answers and the provider interface
load_policy(source) function Load and validate a policy from a path, dict or Policy
explain(policy, capability, arguments, *, working_directory, environment) function The data behind agentguard explain
__version__ str Installed version

Guard

Member Purpose
tool(*, capability, name, sandboxed, executor, verifier, path_arg, url_arg, command_arg, content_arg, recipient_args) Decorator that registers a tool
call(name, arguments) / await acall(name, arguments) Dispatch by name
new_session(agent_id=None) A Session with call, acall, with binding, state, summary
default_session The session used when none is bound
tools Registered tool names
capabilities Built-in plus policy-declared capabilities
summary Count of evaluated decisions by effect
session_id, session Session identity and risk state

Constructor options: mode is "enforce" or "dry-run"; context is {"working_directory", "environment", "user"}; approval_timeout is in seconds.

Other public modules

Module Names
agentguard.approval Approval, ApprovalProvider, ApprovalStore, QueueApproval, CLIApproval, SlackNotifier, WebhookNotifier
agentguard.approval.webhook verify_signature
agentguard.audit.logger AuditLogger
agentguard.audit.export LoggingExporter, HttpExporter
agentguard.audit.reader read_log
agentguard.audit.report build_report, format_report
agentguard.core.ratelimit LocalRateLimiter, RedisRateLimiter
agentguard.dashboard.app create_app
agentguard.execution ContainerExecutor, FilesystemExecutor, ShellExecutor, NetworkExecutor, WorkspaceVerifier
agentguard.execution.egress EgressProxy
agentguard.risk.commands analyze, assess
agentguard.risk.secrets detect_secrets, detect_pii, detect_sensitive, redact
agentguard.bench.judge load_cases, run_benchmark, summarize
agentguard.adapters.langchain guarded_tool, from_guarded
agentguard.adapters.openai_agents guarded_tool, from_guarded
agentguard.adapters.adk guarded_tool, from_guarded
agentguard.adapters.mcp register_tool
agentguard.adapters.python GuardMiddleware
agentguard.risk.gemma_judge GemmaJudge, OllamaClient

The package ships py.typed.