Skip to content
Metamynd
Developers

An agent should not be the thing that decides what it is allowed to do

Metamynd is the server-authoritative gate that decides instead. Your agent signs what it intends to do; the gate checks it against a mandate you issued and rules you control, and answers allow, observe, block or escalate. One command, no account:

npx create-metamynd-agent --sandbox
Guard SDK

Govern a tool in a few lines

Wrap any tool with the guard: it runs only when MetaMynd allows, and refuses blocked or escalated actions — governance decided by policy, not the LLM.

govern-a-tool.ts
import { createGuardFromConfig } from "@metamynd/agentsafe-guard";

// Load the config the onboarding call returned.
const guard = await createGuardFromConfig("./agent.metamynd.json");

// Wrap any tool — it runs ONLY if MetaMynd allows.
const bookFlight = guard.guardTool(
  "flight-purchase",                     // = your mandate scope
  rawBookFlight,                         // your existing handler
  (a) => ({ amount: a.amount, currency: "USD", merchant: a.merchant,
            context: { riskLevel: a.riskLevel } }),
);

// $400 → allow · $600 → block (SOP_SPEND_CAP) · high-risk → escalate
Open protocol

MAGP v1.0 — the specification

Every authorization decision this platform makes is defined by a published protocol: agent identity, the canonical signed message, the sixteen-stage order of checks, every reason code, delegation narrowing and offline-verifiable evidence. Implement it, verify against it, or re-implement the gate yourself.

No licence required, and no account needed to call any endpoint the spec names as public — including the authorize gate itself.

Deploy wizard

Starter rule packs

Pick a governance rule set at deploy time — spend caps and risk review, or a pack mapped to a specific regulation, bill, or standard (EU AI Act, Malaysia's proposed AI Governance Bill, SAFR, the UK's AI Risk Management Toolkit). Live from the same catalog the wizard offers.

Capabilities

Everything you need to build trustworthy AI

One-call provisioning

POST /onboarding/agent issues an identity + mandate + Standards and returns a portable config.

Zero-dependency Guard SDK

@metamynd/agentsafe-guard gates any Node agent's tools — allow, observe, block or escalate — fail-closed.

@metamynd/agentsafe-guard on npm

Scaffolding CLI

npx create-metamynd-agent logs in, provisions and drops a runnable governed agent.

create-metamynd-agent on npm

Public sandbox

A no-KYB endpoint hands you a ready sandbox agent — first decision in minutes.

Bring-your-own-key

Register a key you control and prove it with verify-key — MetaMynd never sees your private key.

Delegated issuance

A developer requests an agent; the owner approves in the dashboard. No shared credentials.

MCP-native, trustless

agentsafe-mcp-guard lets a service re-verify a signed request against the agent's policy bundle, deny-by-default on any amount it can't determine.

@metamynd/agentsafe-mcp-guard on npm

A2A-native, trustless

agentsafe-a2a-guard lets the RECEIVING agent independently re-verify a caller's signed request before a delegated task ever runs — no mutual handshake needed, since A2A already has its own transport auth and discovery.

@metamynd/agentsafe-a2a-guard on npm

Signed policy bundles

Evaluate the same deterministic policy locally, or trustlessly at the edge — no round-trip.

Tamper-proof evidence

Every decision is Ed25519-signed and anchored — offline-verifiable in the regulator log.

Local key custody, out of the guard's own process

agentsafe-signer is a separate daemon holding an agent's or service's signing key — the guard never sees it. An early implementation pass, not the finished design; see its own README for exactly what's verified vs. still open.

@metamynd/agentsafe-signer on npm

Self-hosted trust graph

@metamynd/mmt-graph is a self-hostable, sovereign trust-graph engine — validate and anchor your own tenant's authority chain, no MetaMynd backend required.

@metamynd/mmt-graph on npm

Start building on Metamynd

Spin up a governed sandbox agent with no account and no KYB — your first allow / observe / block / escalate in minutes.