{"_id":"@axiru/agt-extension","name":"@axiru/agt-extension","dist-tags":{"latest":"0.1.0"},"versions":{"0.1.0":{"name":"@axiru/agt-extension","version":"0.1.0","description":"Axiru extension for the Microsoft Agent Governance Toolkit (AGT). Routes payment-action tool calls to Axiru's policy engine; non-payment tool calls fall through to AGT's defaults.","license":"Apache-2.0","private":false,"author":{"name":"Axiru"},"homepage":"https://axiru.com/agt-extension","repository":{"type":"git","url":"git+https://github.com/AxiruAI/axiru-oss.git","directory":"packages/agt-extension"},"bugs":{"url":"https://github.com/AxiruAI/axiru-oss/issues"},"keywords":["axiru","agt","agent-governance","agent-governance-toolkit","microsoft-agt","policy","payments","stripe","refund-governance","ai-agents"],"type":"module","main":"dist/src/index.js","types":"dist/src/index.d.ts","exports":{".":{"types":"./dist/src/index.d.ts","import":"./dist/src/index.js"}},"engines":{"node":">=18"},"scripts":{"build":"tsc -p tsconfig.json","lint":"tsc --noEmit","typecheck":"tsc --noEmit","test":"tsc -p tsconfig.json && node dist/test/extension.test.js","prepack":"pnpm run build"},"devDependencies":{"@types/node":"^25.9.1","typescript":"^5.6.3"},"publishConfig":{"access":"public","provenance":true},"gitHead":"9601ad2c5bda7c27bbf866b78f390fc0f3ee8ee7","_id":"@axiru/agt-extension@0.1.0","_nodeVersion":"24.13.1","_npmVersion":"11.8.0","dist":{"integrity":"sha512-x31nlkw1yERehPq4XkxzfcgEfH2YmgpdISezFHKfaDSf/K3KQcHv23Rg/qGm/ceHvSt+euZHEpJlJ6vzkuc/Jg==","shasum":"9944cded4ba65a0aa24af539f81f3036ca333870","tarball":"https://registry.npmjs.org/@axiru/agt-extension/-/agt-extension-0.1.0.tgz","fileCount":18,"unpackedSize":40417,"signatures":[{"keyid":"SHA256:DhQ8wR5APBvFHLF/+Tc+AYvPOdTpcIDqOhxsBHRwC7U","sig":"MEQCIER/RHn6vveYTIeP+r47/eMCfephpm7kCx+XoEKpzmQ1AiA4YtYcX9jDeJowI7mig3NlFH7z7aICC4Cc2+T3/kDnjw=="}]},"_npmUser":{"name":"axiru","email":"marcos@axiru.com"},"directories":{},"maintainers":[{"name":"axiru","email":"marcos@axiru.com"}],"_npmOperationalInternal":{"host":"s3://npm-registry-packages-npm-production","tmp":"tmp/agt-extension_0.1.0_1785886230598_0.9547154592626796"},"_hasShrinkwrap":false}},"time":{"created":"2026-08-04T23:30:30.407Z","0.1.0":"2026-08-04T23:30:30.750Z","modified":"2026-08-04T23:30:30.987Z"},"maintainers":[{"name":"axiru","email":"marcos@axiru.com"}],"description":"Axiru extension for the Microsoft Agent Governance Toolkit (AGT). Routes payment-action tool calls to Axiru's policy engine; non-payment tool calls fall through to AGT's defaults.","homepage":"https://axiru.com/agt-extension","keywords":["axiru","agt","agent-governance","agent-governance-toolkit","microsoft-agt","policy","payments","stripe","refund-governance","ai-agents"],"repository":{"type":"git","url":"git+https://github.com/AxiruAI/axiru-oss.git","directory":"packages/agt-extension"},"author":{"name":"Axiru"},"bugs":{"url":"https://github.com/AxiruAI/axiru-oss/issues"},"license":"Apache-2.0","readme":"# @axiru/agt-extension\n\nAxiru extension for the [Microsoft Agent Governance Toolkit (AGT)](https://github.com/microsoft/agent-governance-toolkit). Routes payment-action tool calls (Stripe, Plaid, ACH, Modern Treasury, Dwolla, Square) to Axiru's policy engine. Non-payment tool calls fall through to AGT's default policies.\n\n**Apache-2.0 licensed. Zero runtime dependencies. About 300 lines of code.**\n\n## What this is\n\nAGT is the seven-package middleware layer Microsoft ships for governing AI agents: policy engine, mesh identity, runtime sandboxing, compliance, marketplace. AGT's default policies cover the broad agent-safety surface (prompt injection, tool-call interception, OWASP Agentic AI Top 10).\n\nThis package fills the one box AGT explicitly does not: **money-moving actions**. Refunds, payouts, ACH transfers, charge captures, and dispute-evidence submissions need human-approval-aware, ledger-backed governance with regulatory audit guarantees. That's what Axiru does, and it's what this extension wires into AGT.\n\n## Installation\n\n```bash\nnpm install @axiru/agt-extension\n# or\npnpm add @axiru/agt-extension\n# or\nyarn add @axiru/agt-extension\n```\n\nRequires Node 18+. Works in Edge runtimes when you pass a custom `fetch`.\n\n## Quickstart\n\n```ts\nimport { GovernanceKernel } from \"@microsoft/agt-core\"; // your AGT version\nimport { AxiruPolicyProvider, AxiruToolCallInterceptor, isPaymentTool } from \"@axiru/agt-extension\";\n\nconst provider = new AxiruPolicyProvider({\n  apiKey: process.env.AXIRU_API_KEY!,\n  // baseUrl: \"https://api.axiru.com\",   // default\n  // failureMode: \"deny\",                 // default; never let payments fire when Axiru is unreachable\n  // timeoutMs: 5_000,                    // default\n});\n\nconst interceptor = new AxiruToolCallInterceptor(provider, isPaymentTool);\n\nconst kernel = new GovernanceKernel({\n  policyPaths: [\"policies/agt.yaml\"],\n  interceptors: [interceptor],            // payment tools route to Axiru; everything else hits AGT defaults\n});\n```\n\n## What gets routed to Axiru\n\nBy default these tool names route to Axiru's `/api/agent/decide` endpoint. Everything else passes through to AGT.\n\n| Service | Tools |\n|---|---|\n| Stripe | `stripe.refund.create`, `stripe.charge.create`, `stripe.charge.capture`, `stripe.payment_intent.create`, `stripe.payment_intent.confirm`, `stripe.payout.create`, `stripe.transfer.create`, `stripe.dispute.update` |\n| Plaid | `plaid.transfer.create`, `plaid.transfer.cancel` |\n| Modern Treasury | `modern_treasury.payment_order.create` |\n| Dwolla | `dwolla.transfer.create` |\n| Square | `square.refund.create`, `square.payment.create` |\n| Custom | Any tool with the `axiru.refund.`, `axiru.charge.`, or `axiru.payment.` prefix |\n\nYou can extend or replace the classifier:\n\n```ts\nimport { buildPaymentToolPredicate } from \"@axiru/agt-extension\";\n\nconst predicate = buildPaymentToolPredicate({\n  toolNames: [...DEFAULT_PAYMENT_TOOL_NAMES, \"acme.invoice.refund\"],\n  toolPrefixes: [\"acme.payout.\"],\n  custom: (name) => name.endsWith(\".transfer\"),\n});\n\nconst interceptor = new AxiruToolCallInterceptor(provider, predicate);\n```\n\n## Failure modes\n\nWhen Axiru's API is unreachable or returns 5xx:\n\n- **`failureMode: \"deny\"`** (default). Payment is denied with a clear reason. Use this for production.\n- **`failureMode: \"allow\"`**. Payment passes through to AGT's default policies. Use this in shadow-mode evaluations where Axiru is observing but not enforcing.\n\n4xx responses (auth failure, validation error) are always treated as authoritative denies regardless of `failureMode`. A misconfigured deployment never gets silently elevated to allow money movement.\n\n## What this is not\n\n- **Not a replacement for AGT.** AGT's default policy engine, mesh identity, prompt-injection detection, and marketplace are unchanged. This extension only intervenes for payment-class tool calls.\n- **Not a general Axiru client.** If you are calling Axiru directly rather than through AGT, use the HTTP API. This package is specifically the AGT bridge.\n- **Not a way to skip the Axiru API key.** You need an Axiru account. Sign up at [axiru.com/start-free](https://axiru.com/start-free).\n\n## Audit trail\n\nEvery payment-class tool call routed through this extension creates a tamper-evident entry in the Axiru ledger with the AGT `agentId`, the tool name, the policy version that decided, and the decision id. AGT's `metadata` field on each decision carries `decisionId` and `policyVersion` so you can join AGT logs to Axiru ledger entries 1:1 without custom integration.\n\n## Versioning\n\nThis package follows semver. Breaking changes to the AGT-side interfaces (e.g. if Microsoft renames `PolicyProviderInterface`) will bump the major. The Axiru API surface (`/api/agent/decide`) is versioned separately and remains backwards compatible across minor bumps of this package.\n\n## Related packages\n\n- [`@axiru/agent-spend-guardrails`](https://www.npmjs.com/package/@axiru/agent-spend-guardrails) runs the same class of policy checks fully in process, with no API key and no network call.\n- [`@axiru/spec`](https://www.npmjs.com/package/@axiru/spec) is the shared policy and evidence vocabulary both packages speak.\n\n## License\n\nApache-2.0. Copyright 2026 Axiru. See [LICENSE](./LICENSE).\n","readmeFilename":"README.md","_rev":"1-f72c91679ccd1b5fd415f9b41e98e198"}