{"_id":"@agentwares/agentguard-sdk","_rev":"4-f7d714e4055f859e96177fb39207d683","name":"@agentwares/agentguard-sdk","dist-tags":{"latest":"0.1.3"},"versions":{"0.1.0":{"name":"@agentwares/agentguard-sdk","version":"0.1.0","keywords":["agentguard","openai-agents","langchain","ai-agents","spend-limit","kill-switch","guardrails","middleware"],"license":"MIT","_id":"@agentwares/agentguard-sdk@0.1.0","maintainers":[{"name":"umerbukhari","email":"umer.bukhari@gmail.com"}],"homepage":"https://github.com/agentwares/agentwares#readme","bugs":{"url":"https://github.com/agentwares/agentwares/issues"},"dist":{"shasum":"fbd8eb6f596560dfc5e2ae80b7b031a2fe5f83d4","tarball":"https://registry.npmjs.org/@agentwares/agentguard-sdk/-/agentguard-sdk-0.1.0.tgz","fileCount":5,"integrity":"sha512-A+0AbcJXbIxLl76JTXAWPs3qRluN+Y4PCxiPk0KVUlCvDBRk9/MA6VqqEHOylfJYMQdClrQ77B6BV7G00dpEBA==","signatures":[{"sig":"MEYCIQD6cvyWz7c1vj8FfoSP2n6xM/KHqkyPZEphESZ+FlNlWgIhAPqtgtFqPdD53s7dCyreByiTwFzdh7YGEc+cMOzBJ6i/","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":67859},"main":"./dist/index.js","type":"module","_from":"file:agentwares-agentguard-sdk-0.1.0.tgz","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"lint":"eslint src","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"umerbukhari","email":"umer.bukhari@gmail.com"},"_resolved":"/private/var/folders/2p/2j2wcvfs4wz6v0nfr4h455k40000gn/T/2f4399bd63cdad353263fbe25a6e9d43/agentwares-agentguard-sdk-0.1.0.tgz","_integrity":"sha512-A+0AbcJXbIxLl76JTXAWPs3qRluN+Y4PCxiPk0KVUlCvDBRk9/MA6VqqEHOylfJYMQdClrQ77B6BV7G00dpEBA==","repository":{"url":"git+https://github.com/agentwares/agentwares.git","type":"git","directory":"packages/agentguard-sdk"},"_npmVersion":"10.9.8","description":"agentguard for tool calls that bypass MCP: wrap OpenAI Agents SDK, LangChain or plain function tools with the same policy engine (spend caps, approvals, kill switch, dry-run, loop breaker, audit log) and cap LLM spend with a guarded fetch.","directories":{},"sideEffects":false,"_nodeVersion":"22.23.2","dependencies":{"@agentwares/agentguard-core":"^0.1.0"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agentguard-sdk_0.1.0_1788483002409_0.41268748712844094","host":"s3://npm-registry-packages-npm-production"}},"0.1.1":{"name":"@agentwares/agentguard-sdk","version":"0.1.1","keywords":["agentguard","openai-agents","langchain","ai-agents","spend-limit","kill-switch","guardrails","middleware"],"license":"MIT","_id":"@agentwares/agentguard-sdk@0.1.1","maintainers":[{"name":"umerbukhari","email":"umer.bukhari@gmail.com"}],"homepage":"https://github.com/agentwares/agentguard/tree/main/packages/agentguard-sdk#readme","bugs":{"url":"https://github.com/agentwares/agentguard/issues"},"dist":{"shasum":"c20f31df63b48aed71492555a24a823d109cbfdb","tarball":"https://registry.npmjs.org/@agentwares/agentguard-sdk/-/agentguard-sdk-0.1.1.tgz","fileCount":5,"integrity":"sha512-DZ6ndXGlLEQyzfoJue83Ig9gLCPTPotnB+7hDxPvaqbA4TsVUhIDRpi7LDlD5lTc33edW/PTfp6heiHPgDDCug==","signatures":[{"sig":"MEUCIQCltMRsSAhX5lkCX91ZU8wqu2Dn+pueqAweiO6iDhiieAIgKdyb68fgn+ogfy7q8fA3PovUfSQrtbOYK4RSt58zqb4=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":68036},"main":"./dist/index.js","type":"module","_from":"file:agentwares-agentguard-sdk-0.1.1.tgz","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"lint":"eslint src","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"umerbukhari","email":"umer.bukhari@gmail.com"},"_resolved":"/private/var/folders/2p/2j2wcvfs4wz6v0nfr4h455k40000gn/T/f00d6d8402bc74469506164876844d01/agentwares-agentguard-sdk-0.1.1.tgz","_integrity":"sha512-DZ6ndXGlLEQyzfoJue83Ig9gLCPTPotnB+7hDxPvaqbA4TsVUhIDRpi7LDlD5lTc33edW/PTfp6heiHPgDDCug==","repository":{"url":"git+https://github.com/agentwares/agentguard.git","type":"git","directory":"packages/agentguard-sdk"},"_npmVersion":"10.9.8","description":"agentguard for tool calls that bypass MCP: wrap OpenAI Agents SDK, LangChain or plain function tools with the same policy engine (spend caps, approvals, kill switch, dry-run, loop breaker, audit log) and cap LLM spend with a guarded fetch.","directories":{},"sideEffects":false,"_nodeVersion":"22.23.2","dependencies":{"@agentwares/agentguard-core":"^0.1.1"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agentguard-sdk_0.1.1_1788806951141_0.2291321825669297","host":"s3://npm-registry-packages-npm-production"}},"0.1.2":{"name":"@agentwares/agentguard-sdk","version":"0.1.2","keywords":["agentguard","openai-agents","langchain","ai-agents","spend-limit","kill-switch","guardrails","middleware"],"license":"MIT","_id":"@agentwares/agentguard-sdk@0.1.2","maintainers":[{"name":"umerbukhari","email":"umer.bukhari@gmail.com"}],"homepage":"https://github.com/agentwares/agentguard/tree/main/packages/agentguard-sdk#readme","bugs":{"url":"https://github.com/agentwares/agentguard/issues"},"dist":{"shasum":"9c2822f2fb69941348c294a826e4f8aac888e6ee","tarball":"https://registry.npmjs.org/@agentwares/agentguard-sdk/-/agentguard-sdk-0.1.2.tgz","fileCount":5,"integrity":"sha512-QyNcj5UCPZHgTzP+GGtDH1YHHwMXaDY71OF+OZBe6GqaYm8/8XeT/Fy8aqo8yxKSxzeuFi5Widp5IEC1nYnLJA==","signatures":[{"sig":"MEUCICdLRMzM7vW43YgubW+igNrI8qKVvredD5fDYyNin18UAiEAtWibI/6DQjcgt6zlebtCx2u/FCYGSEhxI+KmevM37Cc=","keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U"}],"unpackedSize":68088},"main":"./dist/index.js","type":"module","_from":"file:agentwares-agentguard-sdk-0.1.2.tgz","types":"./dist/index.d.ts","engines":{"node":">=20"},"exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"scripts":{"lint":"eslint src","test":"vitest run","build":"tsup","typecheck":"tsc --noEmit"},"_npmUser":{"name":"umerbukhari","email":"umer.bukhari@gmail.com"},"_resolved":"/private/var/folders/2p/2j2wcvfs4wz6v0nfr4h455k40000gn/T/c11c53e33ff8fd1c9710672fd1ea3ae9/agentwares-agentguard-sdk-0.1.2.tgz","_integrity":"sha512-QyNcj5UCPZHgTzP+GGtDH1YHHwMXaDY71OF+OZBe6GqaYm8/8XeT/Fy8aqo8yxKSxzeuFi5Widp5IEC1nYnLJA==","repository":{"url":"git+https://github.com/agentwares/agentguard.git","type":"git","directory":"packages/agentguard-sdk"},"_npmVersion":"10.9.8","description":"agentguard for tool calls that bypass MCP: wrap OpenAI Agents SDK, LangChain or plain function tools with the same policy engine (spend caps, approvals, kill switch, dry-run, loop breaker, audit log) and cap LLM spend with a guarded fetch.","directories":{},"sideEffects":false,"_nodeVersion":"22.23.2","dependencies":{"@agentwares/agentguard-core":"^0.1.2"},"publishConfig":{"access":"public"},"_hasShrinkwrap":false,"_npmOperationalInternal":{"tmp":"tmp/agentguard-sdk_0.1.2_1788807207887_0.3591920126268311","host":"s3://npm-registry-packages-npm-production"}},"0.1.3":{"name":"@agentwares/agentguard-sdk","version":"0.1.3","description":"agentguard for tool calls that bypass MCP: wrap OpenAI Agents SDK, LangChain or plain function tools with the same policy engine (spend caps, approvals, kill switch, dry-run, loop breaker, audit log) and cap LLM spend with a guarded fetch.","license":"MIT","type":"module","main":"./dist/index.js","types":"./dist/index.d.ts","exports":{".":{"types":"./dist/index.d.ts","import":"./dist/index.js"}},"publishConfig":{"access":"public"},"repository":{"type":"git","url":"git+https://github.com/agentwares/agentguard.git","directory":"packages/agentguard-sdk"},"keywords":["agentguard","openai-agents","langchain","ai-agents","spend-limit","kill-switch","guardrails","middleware"],"sideEffects":false,"engines":{"node":">=20"},"dependencies":{"@agentwares/agentguard-core":"^0.1.3"},"homepage":"https://github.com/agentwares/agentguard#readme","bugs":{"url":"https://github.com/agentwares/agentguard/issues"},"scripts":{"build":"tsup","typecheck":"tsc --noEmit","lint":"eslint src","test":"vitest run"},"_id":"@agentwares/agentguard-sdk@0.1.3","_integrity":"sha512-32jF1xbpP/tatF6/IUARGWeSojZsXx35xo2GkCOX2Zx1T/AiNWAUpHoru6fYgvCIBtp/GCjolkNOIGW3x7WcsA==","_resolved":"/private/var/folders/2p/2j2wcvfs4wz6v0nfr4h455k40000gn/T/c21f7c0b578ae2a2ed21ef26cb41c232/agentwares-agentguard-sdk-0.1.3.tgz","_from":"file:agentwares-agentguard-sdk-0.1.3.tgz","_nodeVersion":"22.23.2","_npmVersion":"10.9.8","dist":{"integrity":"sha512-32jF1xbpP/tatF6/IUARGWeSojZsXx35xo2GkCOX2Zx1T/AiNWAUpHoru6fYgvCIBtp/GCjolkNOIGW3x7WcsA==","shasum":"20536ce545d34086446ec74ad0076f68c7fe959e","tarball":"https://registry.npmjs.org/@agentwares/agentguard-sdk/-/agentguard-sdk-0.1.3.tgz","fileCount":6,"unpackedSize":68959,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEUCIHhSlPc7RXav3Z4X/P22dzx8iZL6/KKLYCwhHozrMVFuAiEA50caoMTesL88ZpgG7RkdJQjd4Nf/QSKMAoRWFWrhuFM="}]},"_npmUser":{"name":"umerbukhari","email":"umer.bukhari@gmail.com"},"directories":{},"maintainers":[{"name":"umerbukhari","email":"umer.bukhari@gmail.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/agentguard-sdk_0.1.3_1788820519080_0.43261202400143484"},"_hasShrinkwrap":false}},"time":{"created":"2026-09-04T00:50:02.244Z","modified":"2026-09-07T22:35:19.387Z","0.1.0":"2026-09-04T00:50:02.544Z","0.1.1":"2026-09-07T18:49:11.265Z","0.1.2":"2026-09-07T18:53:28.046Z","0.1.3":"2026-09-07T22:35:19.214Z"},"bugs":{"url":"https://github.com/agentwares/agentguard/issues"},"license":"MIT","homepage":"https://github.com/agentwares/agentguard#readme","keywords":["agentguard","openai-agents","langchain","ai-agents","spend-limit","kill-switch","guardrails","middleware"],"repository":{"type":"git","url":"git+https://github.com/agentwares/agentguard.git","directory":"packages/agentguard-sdk"},"description":"agentguard for tool calls that bypass MCP: wrap OpenAI Agents SDK, LangChain or plain function tools with the same policy engine (spend caps, approvals, kill switch, dry-run, loop breaker, audit log) and cap LLM spend with a guarded fetch.","maintainers":[{"name":"umerbukhari","email":"umer.bukhari@gmail.com"}],"readme":"# @agentwares/agentguard-sdk\n\nThe [agentguard](https://github.com/agentwares/agentguard/tree/main/apps/agentguard-cli#readme) policy engine for tool calls that never go through MCP — OpenAI Agents SDK, LangChain, or plain functions — plus a guarded `fetch` that puts a **hard dollar limit on LLM token spend** across OpenAI, Anthropic and Gemini. Same `agentguard.yaml`, same caps, kill switch, approvals, dry-run and hash-chained audit log as the proxy; the CLI (`agentguard report`, `kill`, `approve`, `verify`) works on the same files.\n\n```sh\nnpm i @agentwares/agentguard-sdk\n```\n\n```ts\nimport { createGuard, createGuardedFetch, wrapOpenAIAgentsTools } from \"@agentwares/agentguard-sdk\";\nimport { Agent, run, tool } from \"@openai/agents\";\nimport OpenAI, { setDefaultOpenAIClient } from \"@openai/agents-openai\";\n\nconst ag = await createGuard({ policy: \"agentguard.yaml\" }); // file-backed: shares state with the CLI\n\n// 1. tools: caps, approvals, loop breaker, dry-run — blocked calls return { code, cause, fix } as the tool output\nconst tools = wrapOpenAIAgentsTools(ag, [deleteContact, sendEmail, chargeCard]);\n\n// 2. tokens: every OpenAI/Anthropic/Gemini response is priced and charged to the same spend_usd caps\nsetDefaultOpenAIClient(new OpenAI({ fetch: createGuardedFetch(ag) }));\n\nawait run(new Agent({ name: \"ops\", tools }), \"clean up stale contacts\");\nconsole.log(await ag.reportMarkdown()); // what it did / would have destroyed / spent\n```\n\n## API\n\n|                                                                      |                                                                                                                                                                                                                                                          |\n| -------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |\n| `createGuard({ policy, runId?, agent?, onEvent?, memory?, env? })`   | `policy` is a path to `agentguard.yaml` (file-backed state, shared with the CLI) or an inline policy object (in-memory). `agent` picks a scope from `agents:`.                                                                                           |\n| `ag.wrap(fn, { name, annotations?, outputSchema?, onBlock? })`       | wrap `(args) => result`; blocked calls throw `GuardError` (or return the body with `onBlock: \"return\"`)                                                                                                                                                  |\n| `ag.wrapAll({ name: fn, … })`                                        | wrap a map of functions by name                                                                                                                                                                                                                          |\n| `wrapOpenAIAgentsTool(s)(ag, tool(s), opts?)`                        | wrap what `tool({...})` returns (duck-typed on `invoke`); blocked → error JSON as the tool output, faked → synthetic JSON                                                                                                                                |\n| `wrapLangChainTool(s)(ag, tool(s), opts?)`                           | wrap a `StructuredTool` / `DynamicStructuredTool`; keeps the prototype, intercepts `_call`                                                                                                                                                               |\n| `createGuardedFetch(ag, { fetch?, runId?, providers?, onSpend? })`   | a `fetch` for `new OpenAI({ fetch })`, `new Anthropic({ fetch })`, Gemini REST: refuses calls once `spend_usd` is used up (402 `CAP_EXCEEDED`, 403 `KILLED`), prices every response (streamed too) with built-in list prices or `spend.models` overrides |\n| `ag.spend(usd, label, { force? })`                                   | record spend from anything else (a paid API); throws `CAP_EXCEEDED` unless `force`                                                                                                                                                                       |\n| `ag.halt(reason)` / `ag.resume()`                                    | kill switch (writes the KILL file when file-backed)                                                                                                                                                                                                      |\n| `ag.pendingApprovals()` / `ag.approve(id)` / `ag.deny(id)`           | approvals                                                                                                                                                                                                                                                |\n| `ag.newRun(id?)` / `ag.runId`                                        | run identity for per-run caps and the loop window                                                                                                                                                                                                        |\n| `ag.status()` / `ag.audit()` / `ag.report()` / `ag.reportMarkdown()` | counters vs caps; the audit entries; the incident-shaped report                                                                                                                                                                                          |\n\nErrors (`GuardError` or the returned body) always carry `{ code, cause, fix, retryable, details? }` with codes `KILLED`, `APPROVAL_REQUIRED`, `APPROVAL_DENIED`, `LOOP_DETECTED`, `CAP_EXCEEDED`, `TOOL_DENIED`, `UPSTREAM_ERROR`.\n\n## Spend on tokens\n\n`createGuardedFetch` recognizes `api.openai.com` (chat completions and responses, streamed or not — OpenAI chat streams get `stream_options.include_usage` added), `api.anthropic.com` (`message_start` + `message_delta` usage) and `generativelanguage.googleapis.com` (`usageMetadata`). Prices: built-in list prices for current Claude / GPT / Gemini families (`DEFAULT_MODEL_PRICES` in core), overridden per pattern in the policy:\n\n```yaml\ncaps:\n  per_run: { spend_usd: 5 }\n  per_day: { spend_usd: 50 }\nspend:\n  models:\n    \"gpt-5*\": { input_per_mtok: 1.25, output_per_mtok: 10, cached_input_per_mtok: 0.125 }\n    \"my-finetune*\": { input_per_mtok: 3, output_per_mtok: 12 }\n```\n\nMoney spent by a response that crosses the cap is still recorded (`reason: over cap after the fact`) and alerts fire; the next call is refused.\n\nA model with no matching price — a fine-tune, or one newer than the built-in table — is recorded at $0 with `reason: no list price for \"<model>\"`, so `agentguard report` shows a model the budget is not covering instead of under-counting it silently. Add it under `spend.models` to bring it back under the cap.\n\n## Tests\n\n`pnpm test` — plain functions, OpenAI-Agents-shaped and LangChain-shaped fakes (no SDK dependency), file-backed state shared with the CLI, guarded fetch with fake OpenAI/Anthropic responses including SSE streams.\n","readmeFilename":"README.md"}