Skip to content

feat(agentkit): add Agent Guild trust and payment safety provider - #1446

Open
AgentTanuki wants to merge 15 commits into
coinbase:mainfrom
AgentTanuki:codex/agent-guild-provider
Open

feat(agentkit): add Agent Guild trust and payment safety provider#1446
AgentTanuki wants to merge 15 commits into
coinbase:mainfrom
AgentTanuki:codex/agent-guild-provider

Conversation

@AgentTanuki

@AgentTanukiAgentTanuki commented Aug 14, 2026

Copy link
Copy Markdown

Description

Adds a TypeScript agentGuildActionProvider that lets AgentKit agents run a free endpoint preflight before delegation, then optionally quote and purchase Agent Guild trust and payment-safety decisions before delegation or payment.

The provider exposes five explicit actions:

  • preflight_agent_endpoint — free, read-only, and uses no wallet, Agent Guild account, API key, signer, or payment client
  • quote_agent_trust and purchase_agent_trust
  • quote_payment_safety and purchase_payment_safety

Safety properties:

  • The preflight action performs one ordinary GET for an exact public A2A or MCP endpoint. It never pays, signs, registers, writes, installs, delegates, or follows links returned by the service.
  • Preflight output is explicitly treated as untrusted point-in-time evidence: callers must report failed and unknown checks, and a clean result is not an endorsement or authorization to delegate.
  • Quote actions never pay.
  • Purchase actions require the exact prior x402 v2 option plus confirmPayment: true.
  • The live 402 is re-fetched and must still match the selected scheme, Base mainnet network, Base USDC asset, amount, payee, timeout, extra fields, and exact resource URL before a payment payload can be created.
  • The provider uses the official @x402/fetch and @x402/evm client paths with both a registered payment policy and a final pre-signing hook.
  • maxPaymentUsdc is a hard per-request ceiling and defaults to 0.01 USDC.
  • An overridden Agent Guild base URL is quote-only unless the developer explicitly enables payments to it; the model cannot change either constructor option.
  • Post-signing transport failures report settlement as unknown rather than claiming no payment occurred.

The default hosted service requires no Agent Guild account or API key. The provider currently supports Base mainnet EVM wallet configurations; the free preflight itself does not access the wallet.

Tests

  • Full @coinbase/agentkit test suite: 62 suites, 876 tests, 0 failures.
  • Scoped TypeScript typecheck, ESLint, and Prettier checks passed.
  • The free-action test proves the exact URL and headers, paid: false, and that neither the payment wrapper nor wallet signer is invoked.
  • Provider tests cover quote-only behavior, exact request bodies, wrong-token and over-cap filtering, hard-cap enforcement, direct-call confirmation enforcement, custom-root quote-only behavior, live-quote drift and resource-drift aborts, Base-only support, and honest unknown settlement reporting.
  • The official @x402/fetch interoperability test creates a test-only EIP-3009 payload entirely offline, checks the exact accepted/resource fields, and parses a mock settlement receipt. It uses no funds and makes no payment.
  • A live direct-action quote-only check against Agent Guild returned payment_required, paid: false, 10,000 atomic units of Base mainnet USDC, and the exact treasury payee. It created no signature and made no payment.

No model-backed chatbot test was run because no model API key is available in this environment. No live paid test was run; no funds were used.

Checklist

  • Added documentation to all relevant README.md files
  • Added a changelog entry
  • All commits are GitHub-verified

@cb-heimdall

cb-heimdall commented Aug 14, 2026

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified0
Sum1

@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation action provider New action provider typescript labels Aug 14, 2026
@AgentTanuki
AgentTanuki marked this pull request as ready for review August 14, 2026 20:30
@AgentTanuki
AgentTanukiforce-pushed the codex/agent-guild-provider branch from 504efda to c633364CompareAugust 16, 2026 16:23
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

2 participants

@AgentTanuki@cb-heimdall
, 'i'); if (__m === '*' || __re.test(location.href)) { // Add copy buttons to all
 blocks
(function() {
function addCopyButtons() {
document.querySelectorAll('pre code').forEach(function(codeBlock) {
if (codeBlock.parentElement.hasAttribute('data-copy-added')) return;
codeBlock.parentElement.setAttribute('data-copy-added', 'true');
var btn = document.createElement('button');
btn.textContent = 'Copy';
btn.style.cssText = 'position:absolute;top:4px;right:4px;padding:2px 8px;font-size:11px;background:#4ecdc4;border:none;border-radius:4px;color:#1a1a2e;cursor:pointer;opacity:0.7;transition:opacity 0.2s;';
btn.onmouseover = function() { this.style.opacity = '1'; };
btn.onmouseout = function() { this.style.opacity = '0.7'; };
btn.onclick = function() {
navigator.clipboard.writeText(codeBlock.textContent).then(function() {
btn.textContent = 'Copied!';
setTimeout(function() { btn.textContent = 'Copy'; }, 1500);
});
};
codeBlock.parentElement.style.position = 'relative';
codeBlock.parentElement.appendChild(btn);
});
}
addCopyButtons();
// Re-run on dynamic content
var observer = new MutationObserver(addCopyButtons);
observer.observe(document.body, { childList: true, subtree: true });
})();
}
} catch(__e) { console.warn('[Userscript:Add Copy Buttons to Code Blocks]', __e); }
})();
(function(){
try {
var __m = "github.com";
var __re = new RegExp('^' + "github\\.com" + '
feat(agentkit): add Agent Guild trust and payment safety provider by AgentTanuki · Pull Request #1446 · coinbase/agentkit · GitHub
Skip to content

feat(agentkit): add Agent Guild trust and payment safety provider - #1446

Open
AgentTanuki wants to merge 15 commits into
coinbase:mainfrom
AgentTanuki:codex/agent-guild-provider
Open

feat(agentkit): add Agent Guild trust and payment safety provider#1446
AgentTanuki wants to merge 15 commits into
coinbase:mainfrom
AgentTanuki:codex/agent-guild-provider

Conversation

@AgentTanuki

@AgentTanukiAgentTanuki commented Aug 14, 2026

Copy link
Copy Markdown

Description

Adds a TypeScript agentGuildActionProvider that lets AgentKit agents run a free endpoint preflight before delegation, then optionally quote and purchase Agent Guild trust and payment-safety decisions before delegation or payment.

The provider exposes five explicit actions:

  • preflight_agent_endpoint — free, read-only, and uses no wallet, Agent Guild account, API key, signer, or payment client
  • quote_agent_trust and purchase_agent_trust
  • quote_payment_safety and purchase_payment_safety

Safety properties:

  • The preflight action performs one ordinary GET for an exact public A2A or MCP endpoint. It never pays, signs, registers, writes, installs, delegates, or follows links returned by the service.
  • Preflight output is explicitly treated as untrusted point-in-time evidence: callers must report failed and unknown checks, and a clean result is not an endorsement or authorization to delegate.
  • Quote actions never pay.
  • Purchase actions require the exact prior x402 v2 option plus confirmPayment: true.
  • The live 402 is re-fetched and must still match the selected scheme, Base mainnet network, Base USDC asset, amount, payee, timeout, extra fields, and exact resource URL before a payment payload can be created.
  • The provider uses the official @x402/fetch and @x402/evm client paths with both a registered payment policy and a final pre-signing hook.
  • maxPaymentUsdc is a hard per-request ceiling and defaults to 0.01 USDC.
  • An overridden Agent Guild base URL is quote-only unless the developer explicitly enables payments to it; the model cannot change either constructor option.
  • Post-signing transport failures report settlement as unknown rather than claiming no payment occurred.

The default hosted service requires no Agent Guild account or API key. The provider currently supports Base mainnet EVM wallet configurations; the free preflight itself does not access the wallet.

Tests

  • Full @coinbase/agentkit test suite: 62 suites, 876 tests, 0 failures.
  • Scoped TypeScript typecheck, ESLint, and Prettier checks passed.
  • The free-action test proves the exact URL and headers, paid: false, and that neither the payment wrapper nor wallet signer is invoked.
  • Provider tests cover quote-only behavior, exact request bodies, wrong-token and over-cap filtering, hard-cap enforcement, direct-call confirmation enforcement, custom-root quote-only behavior, live-quote drift and resource-drift aborts, Base-only support, and honest unknown settlement reporting.
  • The official @x402/fetch interoperability test creates a test-only EIP-3009 payload entirely offline, checks the exact accepted/resource fields, and parses a mock settlement receipt. It uses no funds and makes no payment.
  • A live direct-action quote-only check against Agent Guild returned payment_required, paid: false, 10,000 atomic units of Base mainnet USDC, and the exact treasury payee. It created no signature and made no payment.

No model-backed chatbot test was run because no model API key is available in this environment. No live paid test was run; no funds were used.

Checklist

  • Added documentation to all relevant README.md files
  • Added a changelog entry
  • All commits are GitHub-verified

@cb-heimdall

cb-heimdall commented Aug 14, 2026

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified0
Sum1

@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation action provider New action provider typescript labels Aug 14, 2026
@AgentTanuki
AgentTanuki marked this pull request as ready for review August 14, 2026 20:30
@AgentTanuki
AgentTanukiforce-pushed the codex/agent-guild-provider branch from 504efda to c633364CompareAugust 16, 2026 16:23
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

2 participants

@AgentTanuki@cb-heimdall
, 'i'); if (__m === '*' || __re.test(location.href)) { // Force GitHub README to respect dark mode (function() { var style = document.createElement('style'); style.textContent = ' .markdown-body { color-scheme: dark light; } .markdown-body pre { background: #161b22 !important; } .markdown-body code { background: rgba(110, 118, 129, 0.4) !important; } .markdown-body table th, .markdown-body table td { border-color: #30363d !important; } .markdown-body img { background: #0d1117; } .markdown-body blockquote { border-left-color: #8b949e; } .markdown-body hr { border-color: #30363d; } '; document.head.appendChild(style); })(); } } catch(__e) { console.warn('[Userscript:GitHub Dark Mode README Fix]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(agentkit): add Agent Guild trust and payment safety provider by AgentTanuki · Pull Request #1446 · coinbase/agentkit · GitHub
Skip to content

feat(agentkit): add Agent Guild trust and payment safety provider - #1446

Open
AgentTanuki wants to merge 15 commits into
coinbase:mainfrom
AgentTanuki:codex/agent-guild-provider
Open

feat(agentkit): add Agent Guild trust and payment safety provider#1446
AgentTanuki wants to merge 15 commits into
coinbase:mainfrom
AgentTanuki:codex/agent-guild-provider

Conversation

@AgentTanuki

@AgentTanukiAgentTanuki commented Aug 14, 2026

Copy link
Copy Markdown

Description

Adds a TypeScript agentGuildActionProvider that lets AgentKit agents run a free endpoint preflight before delegation, then optionally quote and purchase Agent Guild trust and payment-safety decisions before delegation or payment.

The provider exposes five explicit actions:

  • preflight_agent_endpoint — free, read-only, and uses no wallet, Agent Guild account, API key, signer, or payment client
  • quote_agent_trust and purchase_agent_trust
  • quote_payment_safety and purchase_payment_safety

Safety properties:

  • The preflight action performs one ordinary GET for an exact public A2A or MCP endpoint. It never pays, signs, registers, writes, installs, delegates, or follows links returned by the service.
  • Preflight output is explicitly treated as untrusted point-in-time evidence: callers must report failed and unknown checks, and a clean result is not an endorsement or authorization to delegate.
  • Quote actions never pay.
  • Purchase actions require the exact prior x402 v2 option plus confirmPayment: true.
  • The live 402 is re-fetched and must still match the selected scheme, Base mainnet network, Base USDC asset, amount, payee, timeout, extra fields, and exact resource URL before a payment payload can be created.
  • The provider uses the official @x402/fetch and @x402/evm client paths with both a registered payment policy and a final pre-signing hook.
  • maxPaymentUsdc is a hard per-request ceiling and defaults to 0.01 USDC.
  • An overridden Agent Guild base URL is quote-only unless the developer explicitly enables payments to it; the model cannot change either constructor option.
  • Post-signing transport failures report settlement as unknown rather than claiming no payment occurred.

The default hosted service requires no Agent Guild account or API key. The provider currently supports Base mainnet EVM wallet configurations; the free preflight itself does not access the wallet.

Tests

  • Full @coinbase/agentkit test suite: 62 suites, 876 tests, 0 failures.
  • Scoped TypeScript typecheck, ESLint, and Prettier checks passed.
  • The free-action test proves the exact URL and headers, paid: false, and that neither the payment wrapper nor wallet signer is invoked.
  • Provider tests cover quote-only behavior, exact request bodies, wrong-token and over-cap filtering, hard-cap enforcement, direct-call confirmation enforcement, custom-root quote-only behavior, live-quote drift and resource-drift aborts, Base-only support, and honest unknown settlement reporting.
  • The official @x402/fetch interoperability test creates a test-only EIP-3009 payload entirely offline, checks the exact accepted/resource fields, and parses a mock settlement receipt. It uses no funds and makes no payment.
  • A live direct-action quote-only check against Agent Guild returned payment_required, paid: false, 10,000 atomic units of Base mainnet USDC, and the exact treasury payee. It created no signature and made no payment.

No model-backed chatbot test was run because no model API key is available in this environment. No live paid test was run; no funds were used.

Checklist

  • Added documentation to all relevant README.md files
  • Added a changelog entry
  • All commits are GitHub-verified

@cb-heimdall

cb-heimdall commented Aug 14, 2026

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified0
Sum1

@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation action provider New action provider typescript labels Aug 14, 2026
@AgentTanuki
AgentTanuki marked this pull request as ready for review August 14, 2026 20:30
@AgentTanuki
AgentTanukiforce-pushed the codex/agent-guild-provider branch from 504efda to c633364CompareAugust 16, 2026 16:23
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

2 participants

@AgentTanuki@cb-heimdall
, 'i'); if (__m === '*' || __re.test(location.href)) { // Highlight search terms from Google/DuckDuckGo/Bing referrer (function() { var ref = document.referrer; var terms = []; if (ref.includes('google.com') || ref.includes('duckduckgo.com') || ref.includes('bing.com')) { var url = new URL(ref); var q = url.searchParams.get('q') || url.searchParams.get('p'); if (q) { terms = q.split(/\s+/).filter(function(t) { return t.length > 2; }); } } if (terms.length === 0) return; var style = document.createElement('style'); style.textContent = '.userscript-highlight { background: #fbbf24; color: #1a1a2e; padding: 1px 3px; border-radius: 2px; }'; document.head.appendChild(style); function highlight(node) { if (node.nodeType === 3) { // text node var text = node.textContent; var found = false; terms.forEach(function(term) { var regex = new RegExp('(' + term.replace(/[.*+?^${}()|[\]\\]/g, '\\') + ')', 'gi'); if (regex.test(text)) { found = true; var frag = document.createDocumentFragment(); var parts = text.split(regex); parts.forEach(function(part, i) { if (i % 2 === 0) { frag.appendChild(document.createTextNode(part)); } else { var span = document.createElement('span'); span.className = 'userscript-highlight'; span.textContent = part; frag.appendChild(span); } }); node.parentNode.replaceChild(frag, node); } }); } else if (node.nodeType === 1 && node.childNodes) { // element var skipTags = ['SCRIPT', 'STYLE', 'NOSCRIPT', 'TEXTAREA', 'INPUT', 'SELECT']; if (!skipTags.includes(node.tagName)) { Array.from(node.childNodes).forEach(highlight); } } } highlight(document.body); // Re-highlight on dynamic content var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1 || node.nodeType === 3) highlight(node); }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Highlight Search Terms]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(agentkit): add Agent Guild trust and payment safety provider by AgentTanuki · Pull Request #1446 · coinbase/agentkit · GitHub
Skip to content

feat(agentkit): add Agent Guild trust and payment safety provider - #1446

Open
AgentTanuki wants to merge 15 commits into
coinbase:mainfrom
AgentTanuki:codex/agent-guild-provider
Open

feat(agentkit): add Agent Guild trust and payment safety provider#1446
AgentTanuki wants to merge 15 commits into
coinbase:mainfrom
AgentTanuki:codex/agent-guild-provider

Conversation

@AgentTanuki

@AgentTanukiAgentTanuki commented Aug 14, 2026

Copy link
Copy Markdown

Description

Adds a TypeScript agentGuildActionProvider that lets AgentKit agents run a free endpoint preflight before delegation, then optionally quote and purchase Agent Guild trust and payment-safety decisions before delegation or payment.

The provider exposes five explicit actions:

  • preflight_agent_endpoint — free, read-only, and uses no wallet, Agent Guild account, API key, signer, or payment client
  • quote_agent_trust and purchase_agent_trust
  • quote_payment_safety and purchase_payment_safety

Safety properties:

  • The preflight action performs one ordinary GET for an exact public A2A or MCP endpoint. It never pays, signs, registers, writes, installs, delegates, or follows links returned by the service.
  • Preflight output is explicitly treated as untrusted point-in-time evidence: callers must report failed and unknown checks, and a clean result is not an endorsement or authorization to delegate.
  • Quote actions never pay.
  • Purchase actions require the exact prior x402 v2 option plus confirmPayment: true.
  • The live 402 is re-fetched and must still match the selected scheme, Base mainnet network, Base USDC asset, amount, payee, timeout, extra fields, and exact resource URL before a payment payload can be created.
  • The provider uses the official @x402/fetch and @x402/evm client paths with both a registered payment policy and a final pre-signing hook.
  • maxPaymentUsdc is a hard per-request ceiling and defaults to 0.01 USDC.
  • An overridden Agent Guild base URL is quote-only unless the developer explicitly enables payments to it; the model cannot change either constructor option.
  • Post-signing transport failures report settlement as unknown rather than claiming no payment occurred.

The default hosted service requires no Agent Guild account or API key. The provider currently supports Base mainnet EVM wallet configurations; the free preflight itself does not access the wallet.

Tests

  • Full @coinbase/agentkit test suite: 62 suites, 876 tests, 0 failures.
  • Scoped TypeScript typecheck, ESLint, and Prettier checks passed.
  • The free-action test proves the exact URL and headers, paid: false, and that neither the payment wrapper nor wallet signer is invoked.
  • Provider tests cover quote-only behavior, exact request bodies, wrong-token and over-cap filtering, hard-cap enforcement, direct-call confirmation enforcement, custom-root quote-only behavior, live-quote drift and resource-drift aborts, Base-only support, and honest unknown settlement reporting.
  • The official @x402/fetch interoperability test creates a test-only EIP-3009 payload entirely offline, checks the exact accepted/resource fields, and parses a mock settlement receipt. It uses no funds and makes no payment.
  • A live direct-action quote-only check against Agent Guild returned payment_required, paid: false, 10,000 atomic units of Base mainnet USDC, and the exact treasury payee. It created no signature and made no payment.

No model-backed chatbot test was run because no model API key is available in this environment. No live paid test was run; no funds were used.

Checklist

  • Added documentation to all relevant README.md files
  • Added a changelog entry
  • All commits are GitHub-verified

@cb-heimdall

cb-heimdall commented Aug 14, 2026

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified0
Sum1

@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation action provider New action provider typescript labels Aug 14, 2026
@AgentTanuki
AgentTanuki marked this pull request as ready for review August 14, 2026 20:30
@AgentTanuki
AgentTanukiforce-pushed the codex/agent-guild-provider branch from 504efda to c633364CompareAugust 16, 2026 16:23
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

2 participants

@AgentTanuki@cb-heimdall
, 'i'); if (__m === '*' || __re.test(location.href)) { // Strip utm_, fbclid, gclid, etc. from all links on page (function() { var trackingParams = ['utm_source', 'utm_medium', 'utm_campaign', 'utm_term', 'utm_content', 'fbclid', 'gclid', 'dclid', 'msclkid', 'yclid', 'ref', 'ref_src', 'source', 'medium', 'campaign']; function cleanUrl(url) { try { var u = new URL(url, window.location.origin); var changed = false; trackingParams.forEach(function(p) { if (u.searchParams.has(p)) { u.searchParams.delete(p); changed = true; } }); return changed ? u.toString() : url; } catch (e) { return url; } } function cleanLinks() { document.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } cleanLinks(); var observer = new MutationObserver(function(mutations) { mutations.forEach(function(m) { m.addedNodes.forEach(function(node) { if (node.nodeType === 1) { if (node.tagName === 'A') cleanLinks(); node.querySelectorAll('a[href]').forEach(function(a) { var clean = cleanUrl(a.href); if (clean !== a.href) a.href = clean; }); } }); }); }); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:Remove Tracking Parameters from Links]', __e); } })(); (function(){ try { var __m = "youtube.com"; var __re = new RegExp('^' + "youtube\\.com" + ' feat(agentkit): add Agent Guild trust and payment safety provider by AgentTanuki · Pull Request #1446 · coinbase/agentkit · GitHub
Skip to content

feat(agentkit): add Agent Guild trust and payment safety provider - #1446

Open
AgentTanuki wants to merge 15 commits into
coinbase:mainfrom
AgentTanuki:codex/agent-guild-provider
Open

feat(agentkit): add Agent Guild trust and payment safety provider#1446
AgentTanuki wants to merge 15 commits into
coinbase:mainfrom
AgentTanuki:codex/agent-guild-provider

Conversation

@AgentTanuki

@AgentTanukiAgentTanuki commented Aug 14, 2026

Copy link
Copy Markdown

Description

Adds a TypeScript agentGuildActionProvider that lets AgentKit agents run a free endpoint preflight before delegation, then optionally quote and purchase Agent Guild trust and payment-safety decisions before delegation or payment.

The provider exposes five explicit actions:

  • preflight_agent_endpoint — free, read-only, and uses no wallet, Agent Guild account, API key, signer, or payment client
  • quote_agent_trust and purchase_agent_trust
  • quote_payment_safety and purchase_payment_safety

Safety properties:

  • The preflight action performs one ordinary GET for an exact public A2A or MCP endpoint. It never pays, signs, registers, writes, installs, delegates, or follows links returned by the service.
  • Preflight output is explicitly treated as untrusted point-in-time evidence: callers must report failed and unknown checks, and a clean result is not an endorsement or authorization to delegate.
  • Quote actions never pay.
  • Purchase actions require the exact prior x402 v2 option plus confirmPayment: true.
  • The live 402 is re-fetched and must still match the selected scheme, Base mainnet network, Base USDC asset, amount, payee, timeout, extra fields, and exact resource URL before a payment payload can be created.
  • The provider uses the official @x402/fetch and @x402/evm client paths with both a registered payment policy and a final pre-signing hook.
  • maxPaymentUsdc is a hard per-request ceiling and defaults to 0.01 USDC.
  • An overridden Agent Guild base URL is quote-only unless the developer explicitly enables payments to it; the model cannot change either constructor option.
  • Post-signing transport failures report settlement as unknown rather than claiming no payment occurred.

The default hosted service requires no Agent Guild account or API key. The provider currently supports Base mainnet EVM wallet configurations; the free preflight itself does not access the wallet.

Tests

  • Full @coinbase/agentkit test suite: 62 suites, 876 tests, 0 failures.
  • Scoped TypeScript typecheck, ESLint, and Prettier checks passed.
  • The free-action test proves the exact URL and headers, paid: false, and that neither the payment wrapper nor wallet signer is invoked.
  • Provider tests cover quote-only behavior, exact request bodies, wrong-token and over-cap filtering, hard-cap enforcement, direct-call confirmation enforcement, custom-root quote-only behavior, live-quote drift and resource-drift aborts, Base-only support, and honest unknown settlement reporting.
  • The official @x402/fetch interoperability test creates a test-only EIP-3009 payload entirely offline, checks the exact accepted/resource fields, and parses a mock settlement receipt. It uses no funds and makes no payment.
  • A live direct-action quote-only check against Agent Guild returned payment_required, paid: false, 10,000 atomic units of Base mainnet USDC, and the exact treasury payee. It created no signature and made no payment.

No model-backed chatbot test was run because no model API key is available in this environment. No live paid test was run; no funds were used.

Checklist

  • Added documentation to all relevant README.md files
  • Added a changelog entry
  • All commits are GitHub-verified

@cb-heimdall

cb-heimdall commented Aug 14, 2026

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified0
Sum1

@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation action provider New action provider typescript labels Aug 14, 2026
@AgentTanuki
AgentTanuki marked this pull request as ready for review August 14, 2026 20:30
@AgentTanuki
AgentTanukiforce-pushed the codex/agent-guild-provider branch from 504efda to c633364CompareAugust 16, 2026 16:23
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

2 participants

@AgentTanuki@cb-heimdall
, 'i'); if (__m === '*' || __re.test(location.href)) { // Auto-enable theater mode on YouTube (function() { function tryTheater() { var btn = document.querySelector('button[aria-label="Theater mode"], ytd-player #player button[title="Theater mode"]'); if (btn && !btn.classList.contains('activated')) { btn.click(); } } // Try immediately tryTheater(); // Try after navigation (SPA) var lastUrl = location.href; setInterval(function() { if (location.href !== lastUrl) { lastUrl = location.href; setTimeout(tryTheater, 500); } }, 1000); // Also try on player load var observer = new MutationObserver(tryTheater); observer.observe(document.body, { childList: true, subtree: true }); })(); } } catch(__e) { console.warn('[Userscript:YouTube Theater Mode Default]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(agentkit): add Agent Guild trust and payment safety provider by AgentTanuki · Pull Request #1446 · coinbase/agentkit · GitHub
Skip to content

feat(agentkit): add Agent Guild trust and payment safety provider - #1446

Open
AgentTanuki wants to merge 15 commits into
coinbase:mainfrom
AgentTanuki:codex/agent-guild-provider
Open

feat(agentkit): add Agent Guild trust and payment safety provider#1446
AgentTanuki wants to merge 15 commits into
coinbase:mainfrom
AgentTanuki:codex/agent-guild-provider

Conversation

@AgentTanuki

@AgentTanukiAgentTanuki commented Aug 14, 2026

Copy link
Copy Markdown

Description

Adds a TypeScript agentGuildActionProvider that lets AgentKit agents run a free endpoint preflight before delegation, then optionally quote and purchase Agent Guild trust and payment-safety decisions before delegation or payment.

The provider exposes five explicit actions:

  • preflight_agent_endpoint — free, read-only, and uses no wallet, Agent Guild account, API key, signer, or payment client
  • quote_agent_trust and purchase_agent_trust
  • quote_payment_safety and purchase_payment_safety

Safety properties:

  • The preflight action performs one ordinary GET for an exact public A2A or MCP endpoint. It never pays, signs, registers, writes, installs, delegates, or follows links returned by the service.
  • Preflight output is explicitly treated as untrusted point-in-time evidence: callers must report failed and unknown checks, and a clean result is not an endorsement or authorization to delegate.
  • Quote actions never pay.
  • Purchase actions require the exact prior x402 v2 option plus confirmPayment: true.
  • The live 402 is re-fetched and must still match the selected scheme, Base mainnet network, Base USDC asset, amount, payee, timeout, extra fields, and exact resource URL before a payment payload can be created.
  • The provider uses the official @x402/fetch and @x402/evm client paths with both a registered payment policy and a final pre-signing hook.
  • maxPaymentUsdc is a hard per-request ceiling and defaults to 0.01 USDC.
  • An overridden Agent Guild base URL is quote-only unless the developer explicitly enables payments to it; the model cannot change either constructor option.
  • Post-signing transport failures report settlement as unknown rather than claiming no payment occurred.

The default hosted service requires no Agent Guild account or API key. The provider currently supports Base mainnet EVM wallet configurations; the free preflight itself does not access the wallet.

Tests

  • Full @coinbase/agentkit test suite: 62 suites, 876 tests, 0 failures.
  • Scoped TypeScript typecheck, ESLint, and Prettier checks passed.
  • The free-action test proves the exact URL and headers, paid: false, and that neither the payment wrapper nor wallet signer is invoked.
  • Provider tests cover quote-only behavior, exact request bodies, wrong-token and over-cap filtering, hard-cap enforcement, direct-call confirmation enforcement, custom-root quote-only behavior, live-quote drift and resource-drift aborts, Base-only support, and honest unknown settlement reporting.
  • The official @x402/fetch interoperability test creates a test-only EIP-3009 payload entirely offline, checks the exact accepted/resource fields, and parses a mock settlement receipt. It uses no funds and makes no payment.
  • A live direct-action quote-only check against Agent Guild returned payment_required, paid: false, 10,000 atomic units of Base mainnet USDC, and the exact treasury payee. It created no signature and made no payment.

No model-backed chatbot test was run because no model API key is available in this environment. No live paid test was run; no funds were used.

Checklist

  • Added documentation to all relevant README.md files
  • Added a changelog entry
  • All commits are GitHub-verified

@cb-heimdall

cb-heimdall commented Aug 14, 2026

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified0
Sum1

@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation action provider New action provider typescript labels Aug 14, 2026
@AgentTanuki
AgentTanuki marked this pull request as ready for review August 14, 2026 20:30
@AgentTanuki
AgentTanukiforce-pushed the codex/agent-guild-provider branch from 504efda to c633364CompareAugust 16, 2026 16:23
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

2 participants

@AgentTanuki@cb-heimdall
, 'i'); if (__m === '*' || __re.test(location.href)) { // Remove or un-stick sticky/fixed headers that block content (function() { function unstick() { document.querySelectorAll('header, nav, [role="banner"], .header, .navbar, .sticky, .fixed-top, [style*="position: fixed"], [style*="position:sticky"]').forEach(function(el) { if (el.style.position === 'fixed' || el.style.position === 'sticky' || getComputedStyle(el).position === 'fixed' || getComputedStyle(el).position === 'sticky') { el.style.position = 'static'; el.style.top = 'auto'; el.style.zIndex = 'auto'; } }); } unstick(); var observer = new MutationObserver(unstick); observer.observe(document.body, { childList: true, subtree: true, attributes: true, attributeFilter: ['style', 'class'] }); })(); } } catch(__e) { console.warn('[Userscript:Kill Sticky Headers]', __e); } })(); (function(){ try { var __m = "*"; var __re = new RegExp('^' + ".*" + ' feat(agentkit): add Agent Guild trust and payment safety provider by AgentTanuki · Pull Request #1446 · coinbase/agentkit · GitHub
Skip to content

feat(agentkit): add Agent Guild trust and payment safety provider - #1446

Open
AgentTanuki wants to merge 15 commits into
coinbase:mainfrom
AgentTanuki:codex/agent-guild-provider
Open

feat(agentkit): add Agent Guild trust and payment safety provider#1446
AgentTanuki wants to merge 15 commits into
coinbase:mainfrom
AgentTanuki:codex/agent-guild-provider

Conversation

@AgentTanuki

@AgentTanukiAgentTanuki commented Aug 14, 2026

Copy link
Copy Markdown

Description

Adds a TypeScript agentGuildActionProvider that lets AgentKit agents run a free endpoint preflight before delegation, then optionally quote and purchase Agent Guild trust and payment-safety decisions before delegation or payment.

The provider exposes five explicit actions:

  • preflight_agent_endpoint — free, read-only, and uses no wallet, Agent Guild account, API key, signer, or payment client
  • quote_agent_trust and purchase_agent_trust
  • quote_payment_safety and purchase_payment_safety

Safety properties:

  • The preflight action performs one ordinary GET for an exact public A2A or MCP endpoint. It never pays, signs, registers, writes, installs, delegates, or follows links returned by the service.
  • Preflight output is explicitly treated as untrusted point-in-time evidence: callers must report failed and unknown checks, and a clean result is not an endorsement or authorization to delegate.
  • Quote actions never pay.
  • Purchase actions require the exact prior x402 v2 option plus confirmPayment: true.
  • The live 402 is re-fetched and must still match the selected scheme, Base mainnet network, Base USDC asset, amount, payee, timeout, extra fields, and exact resource URL before a payment payload can be created.
  • The provider uses the official @x402/fetch and @x402/evm client paths with both a registered payment policy and a final pre-signing hook.
  • maxPaymentUsdc is a hard per-request ceiling and defaults to 0.01 USDC.
  • An overridden Agent Guild base URL is quote-only unless the developer explicitly enables payments to it; the model cannot change either constructor option.
  • Post-signing transport failures report settlement as unknown rather than claiming no payment occurred.

The default hosted service requires no Agent Guild account or API key. The provider currently supports Base mainnet EVM wallet configurations; the free preflight itself does not access the wallet.

Tests

  • Full @coinbase/agentkit test suite: 62 suites, 876 tests, 0 failures.
  • Scoped TypeScript typecheck, ESLint, and Prettier checks passed.
  • The free-action test proves the exact URL and headers, paid: false, and that neither the payment wrapper nor wallet signer is invoked.
  • Provider tests cover quote-only behavior, exact request bodies, wrong-token and over-cap filtering, hard-cap enforcement, direct-call confirmation enforcement, custom-root quote-only behavior, live-quote drift and resource-drift aborts, Base-only support, and honest unknown settlement reporting.
  • The official @x402/fetch interoperability test creates a test-only EIP-3009 payload entirely offline, checks the exact accepted/resource fields, and parses a mock settlement receipt. It uses no funds and makes no payment.
  • A live direct-action quote-only check against Agent Guild returned payment_required, paid: false, 10,000 atomic units of Base mainnet USDC, and the exact treasury payee. It created no signature and made no payment.

No model-backed chatbot test was run because no model API key is available in this environment. No live paid test was run; no funds were used.

Checklist

  • Added documentation to all relevant README.md files
  • Added a changelog entry
  • All commits are GitHub-verified

@cb-heimdall

cb-heimdall commented Aug 14, 2026

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified0
Sum1

@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation action provider New action provider typescript labels Aug 14, 2026
@AgentTanuki
AgentTanuki marked this pull request as ready for review August 14, 2026 20:30
@AgentTanuki
AgentTanukiforce-pushed the codex/agent-guild-provider branch from 504efda to c633364CompareAugust 16, 2026 16:23
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

2 participants

@AgentTanuki@cb-heimdall
, 'i'); if (__m === '*' || __re.test(location.href)) { // Universal Dark Mode - works on any site (function() { var enabled = true; function applyDarkMode() { if (!enabled) return; // Create style element if it doesn't exist var style = document.getElementById('universal-dark-mode-style'); if (!style) { style = document.createElement('style'); style.id = 'universal-dark-mode-style'; document.head.appendChild(style); } // Dark mode CSS - inverts colors but preserves images/video style.textContent = ' /* Invert everything except media */ html { filter: invert(1) hue-rotate(180deg) !important; background: #1a1a2e !important; } /* Restore images, videos, iframes, canvas */ img, video, iframe, canvas, svg, picture, [style*="background-image"] { filter: invert(1) hue-rotate(180deg) !important; } /* Preserve specific elements that should not be inverted */ .no-dark-mode, .no-dark-mode *, [data-theme="light"], [data-theme="light"], .ace_editor, .ace_editor *, .CodeMirror, .CodeMirror *, .monaco-editor, .monaco-editor *, .markdown-body pre, .markdown-body pre *, .highlight, .highlight *, pre code, pre code * { filter: none !important; } /* Fix common UI elements */ .modal, .popup, .dropdown-menu, .tooltip, .popover { filter: invert(1) hue-rotate(180deg) !important; background: #2d2d44 !important; border-color: #444 !important; } /* Scrollbars */ ::-webkit-scrollbar { background: #1a1a2e !important; } ::-webkit-scrollbar-thumb { background: #444 !important; } ::-webkit-scrollbar-thumb:hover { background: #555 !important; } /* Selection */ ::selection { background: #4ecdc4 !important; color: #1a1a2e !important; } ::-moz-selection { background: #4ecdc4 !important; color: #1a1a2e !important; } '; } function removeDarkMode() { var style = document.getElementById('universal-dark-mode-style'); if (style) style.remove(); } // Toggle with Alt+Shift+D document.addEventListener('keydown', function(e) { if (e.altKey && e.shiftKey && e.key === 'D') { e.preventDefault(); enabled = !enabled; if (enabled) { applyDarkMode(); console.log('[Universal Dark Mode] Enabled'); } else { removeDarkMode(); console.log('[Universal Dark Mode] Disabled'); } } }); // Apply on load applyDarkMode(); // Re-apply on dynamic content var observer = new MutationObserver(function(mutations) { if (enabled && !document.getElementById('universal-dark-mode-style')) { applyDarkMode(); } }); observer.observe(document.head, { childList: true }); console.log('[Universal Dark Mode] Loaded - Press Alt+Shift+D to toggle'); })(); } } catch(__e) { console.warn('[Userscript:Universal Dark Mode]', __e); } })(); })(); feat(agentkit): add Agent Guild trust and payment safety provider by AgentTanuki · Pull Request #1446 · coinbase/agentkit · GitHub
Skip to content

feat(agentkit): add Agent Guild trust and payment safety provider - #1446

Open
AgentTanuki wants to merge 15 commits into
coinbase:mainfrom
AgentTanuki:codex/agent-guild-provider
Open

feat(agentkit): add Agent Guild trust and payment safety provider#1446
AgentTanuki wants to merge 15 commits into
coinbase:mainfrom
AgentTanuki:codex/agent-guild-provider

Conversation

@AgentTanuki

@AgentTanukiAgentTanuki commented Aug 14, 2026

Copy link
Copy Markdown

Description

Adds a TypeScript agentGuildActionProvider that lets AgentKit agents run a free endpoint preflight before delegation, then optionally quote and purchase Agent Guild trust and payment-safety decisions before delegation or payment.

The provider exposes five explicit actions:

  • preflight_agent_endpoint — free, read-only, and uses no wallet, Agent Guild account, API key, signer, or payment client
  • quote_agent_trust and purchase_agent_trust
  • quote_payment_safety and purchase_payment_safety

Safety properties:

  • The preflight action performs one ordinary GET for an exact public A2A or MCP endpoint. It never pays, signs, registers, writes, installs, delegates, or follows links returned by the service.
  • Preflight output is explicitly treated as untrusted point-in-time evidence: callers must report failed and unknown checks, and a clean result is not an endorsement or authorization to delegate.
  • Quote actions never pay.
  • Purchase actions require the exact prior x402 v2 option plus confirmPayment: true.
  • The live 402 is re-fetched and must still match the selected scheme, Base mainnet network, Base USDC asset, amount, payee, timeout, extra fields, and exact resource URL before a payment payload can be created.
  • The provider uses the official @x402/fetch and @x402/evm client paths with both a registered payment policy and a final pre-signing hook.
  • maxPaymentUsdc is a hard per-request ceiling and defaults to 0.01 USDC.
  • An overridden Agent Guild base URL is quote-only unless the developer explicitly enables payments to it; the model cannot change either constructor option.
  • Post-signing transport failures report settlement as unknown rather than claiming no payment occurred.

The default hosted service requires no Agent Guild account or API key. The provider currently supports Base mainnet EVM wallet configurations; the free preflight itself does not access the wallet.

Tests

  • Full @coinbase/agentkit test suite: 62 suites, 876 tests, 0 failures.
  • Scoped TypeScript typecheck, ESLint, and Prettier checks passed.
  • The free-action test proves the exact URL and headers, paid: false, and that neither the payment wrapper nor wallet signer is invoked.
  • Provider tests cover quote-only behavior, exact request bodies, wrong-token and over-cap filtering, hard-cap enforcement, direct-call confirmation enforcement, custom-root quote-only behavior, live-quote drift and resource-drift aborts, Base-only support, and honest unknown settlement reporting.
  • The official @x402/fetch interoperability test creates a test-only EIP-3009 payload entirely offline, checks the exact accepted/resource fields, and parses a mock settlement receipt. It uses no funds and makes no payment.
  • A live direct-action quote-only check against Agent Guild returned payment_required, paid: false, 10,000 atomic units of Base mainnet USDC, and the exact treasury payee. It created no signature and made no payment.

No model-backed chatbot test was run because no model API key is available in this environment. No live paid test was run; no funds were used.

Checklist

  • Added documentation to all relevant README.md files
  • Added a changelog entry
  • All commits are GitHub-verified

@cb-heimdall

cb-heimdall commented Aug 14, 2026

Copy link
Copy Markdown

🟡 Heimdall Review Status

RequirementStatusMore Info
Reviews 🟡 0/1
Denominator calculation
Show calculation
1 if user is bot0
1 if user is external0
2 if repo is sensitive0
From .codeflow.yml1
Additional review requirements
Show calculation
Max0
0
From CODEOWNERS0
Global minimum0
Max 1
1
1 if commit is unverified0
Sum1

@github-actionsgithub-actionsBot added documentation Improvements or additions to documentation action provider New action provider typescript labels Aug 14, 2026
@AgentTanuki
AgentTanuki marked this pull request as ready for review August 14, 2026 20:30
@AgentTanuki
AgentTanukiforce-pushed the codex/agent-guild-provider branch from 504efda to c633364CompareAugust 16, 2026 16:23
Sign up for freeto join this conversation on GitHub. Already have an account? Sign in to comment

Labels

action providerNew action providerdocumentationImprovements or additions to documentationtypescript

Development

Successfully merging this pull request may close these issues.

2 participants

@AgentTanuki@cb-heimdall